diff options
| author | Florian Westphal <fw@strlen.de> | 2025-11-19 22:36:41 +0300 |
|---|---|---|
| committer | Florian Westphal <fw@strlen.de> | 2026-01-20 18:23:37 +0300 |
| commit | f7becf0dad8f558832a64183c7b1d0c65d327947 (patch) | |
| tree | 869d1cb6234e91be2a7aec4f5d9e25f73c6e5138 | |
| parent | 21d033e472735ecec677f1ae46d6740b5e47a4f3 (diff) | |
| download | linux-f7becf0dad8f558832a64183c7b1d0c65d327947.tar.xz | |
netfilter: nf_conntrack: enable icmp clash support
Not strictly required, but should not be harmful either:
This isn't a stateful protocol, hence clash resolution should work fine.
Signed-off-by: Florian Westphal <fw@strlen.de>
| -rw-r--r-- | net/netfilter/nf_conntrack_proto_icmp.c | 1 | ||||
| -rw-r--r-- | net/netfilter/nf_conntrack_proto_icmpv6.c | 1 |
2 files changed, 2 insertions, 0 deletions
diff --git a/net/netfilter/nf_conntrack_proto_icmp.c b/net/netfilter/nf_conntrack_proto_icmp.c index b38b7164acd5..32148a3a8509 100644 --- a/net/netfilter/nf_conntrack_proto_icmp.c +++ b/net/netfilter/nf_conntrack_proto_icmp.c @@ -365,6 +365,7 @@ void nf_conntrack_icmp_init_net(struct net *net) const struct nf_conntrack_l4proto nf_conntrack_l4proto_icmp = { .l4proto = IPPROTO_ICMP, + .allow_clash = true, #if IS_ENABLED(CONFIG_NF_CT_NETLINK) .tuple_to_nlattr = icmp_tuple_to_nlattr, .nlattr_tuple_size = icmp_nlattr_tuple_size, diff --git a/net/netfilter/nf_conntrack_proto_icmpv6.c b/net/netfilter/nf_conntrack_proto_icmpv6.c index 327b8059025d..e508b3aa370a 100644 --- a/net/netfilter/nf_conntrack_proto_icmpv6.c +++ b/net/netfilter/nf_conntrack_proto_icmpv6.c @@ -343,6 +343,7 @@ void nf_conntrack_icmpv6_init_net(struct net *net) const struct nf_conntrack_l4proto nf_conntrack_l4proto_icmpv6 = { .l4proto = IPPROTO_ICMPV6, + .allow_clash = true, #if IS_ENABLED(CONFIG_NF_CT_NETLINK) .tuple_to_nlattr = icmpv6_tuple_to_nlattr, .nlattr_tuple_size = icmpv6_nlattr_tuple_size, |
