[Bug 443] 2.6 kernel failing in NAT with significant outbound traffic

Tue Feb 21 04:15:25 CET 2006


------- Additional Comments From nothingel at hotmail.com  2006-02-21 04:15 MET -------
Hmm, I don't seem to have a "/proc/sys/net/ipv4/netfilter/ipt_LOG" but I did
find a "/proc/sys/net/ipv4/netfilter/ip_conntrack_log_invalid" and so I set it
to 255.

Upon failing (with the "liberal" option set to 0), I see the following in the log:

kernel: ip_ct_tcp: ACK is over the upper bound (ACKed data not seen yet).

