path: root/conntrackd.8
diff options
author/C=EU/ST=EU/CN=Pablo Neira Ayuso/ </C=EU/ST=EU/CN=Pablo Neira Ayuso/>2007-12-21 13:20:04 +0000
committer/C=EU/ST=EU/CN=Pablo Neira Ayuso/ </C=EU/ST=EU/CN=Pablo Neira Ayuso/>2007-12-21 13:20:04 +0000
commita2eb348ebb6bb3172aa46dd132befe2a24c2d302 (patch)
tree390c79ffc80e9f2cbf45b42ffeda51245748403c /conntrackd.8
parent3c5e35974c65f4470e6543c2cc772c0f1824dc44 (diff)
= conntrack =
o fix missing `-g' and `-n' options in getopt_long control string o add support for secmark (requires Linux kernel >= 2.6.25) o add mark and secmark information to the manpage o cleanup error message = conntrackd = o add support for secmark (requires Linux kernel >= 2.6.25) o add conntrackd (8) manpage
Diffstat (limited to 'conntrackd.8')
1 files changed, 81 insertions, 0 deletions
diff --git a/conntrackd.8 b/conntrackd.8
new file mode 100644
index 0000000..8e2f2cc
--- /dev/null
+++ b/conntrackd.8
@@ -0,0 +1,81 @@
+.TH CONNTRACKD 8 "Dec 21, 2007" "" ""
+.\" Man page written by Pablo Neira Ayuso <> (Dec 2007)
+conntrackd \- netfilter connection tracking userspace daemon
+.BR "conntrackd [options]"
+.B conntrackd
+provides a userspace daemon for the netfilter connection tracking system. This daemon synchronizes connection tracking states among several replica firewalls. Thus,
+.B conntrackd
+can be used to implement highly available stateful firewalls. The daemon fully supports Primary-Backup and Multiprimary setups for both symmetric and asymmetric paths. It can also be used as statistics collector.
+The options recognized by
+.B conntrackd
+can be divided into several different groups.
+These options specify the particular operation mode in which conntrackd runs. Only one of them can be specified at any given time.
+.BI "-d "
+Run conntrackd in daemon mode. This option can be combined with "-S"
+.BI "-S "
+Run conntrackd in statistics mode. Default mode is synchronization mode, so if you want to use
+.B conntrackd
+in statistics mode, you have to pass this option
+.B conntrackd
+can be used in client mode to request several information and operations to a running daemon
+.BI "-i "
+Dump the internal cache, i.e. show local states
+.BI "-e "
+Dump the external cache, i.e. show foreign states
+.BI "-x "
+Display output in XML format. This option is only valid in combination
+with "-i" and "-e" parameters.
+.BI "-f "
+Flush the internal and the external cache
+.BI "-k "
+Kill the daemon
+.BI "-s "
+Dump statistics
+.BI "-R "
+Force a resync against the kernel connection tracking table
+The exit code is 0 for correct function. Errors cause an exit code of 1.
+.B conntrackd \-d
+Runs conntrackd in daemon and synchronization mode
+.B conntrackd \-i
+Dumps the states held in the internal cache, i.e. those handled by this firewall
+.B conntrackd \-e
+Dumps the states held in the external cache, i.e. those handled by other replica firewalls
+.B conntrackd \-c
+Commits the internal cache into the kernel connection tracking system. This is used to inject the state so that the connections can be recovered during the failover.
+This daemon requires a Linux kernel version >= 2.6.18. TCP window tracking support requires >= 2.6.22, otherwise you have to disable it. Helpers are fully supported since >= 2.6.25, however, if you use any previous version, depending on the protocol helper and your setup (e.g. if you setup performs NAT sequence adjustments or not), your help connection may be successfully recovered.
+There are several unsupported stateful iptables matches such as recent, connbytes and the quota matches which gather internal information to operate. Since that information does not belong to the domain of the connection tracking system, connections affected by those matches may not be fully recovered during the takeover.
+.BR conntrack (8), iptables (8)
+.BR ""
+Pablo Neira Ayuso wrote and maintains the conntrackd tool
+Please send bug reports to <>. Subscription is required.
+Man page written by Pablo Neira Ayuso <>.