From 005a06f6e838bb2d3103985415486b3714f73d23 Mon Sep 17 00:00:00 2001 From: Vadim Kochan Date: Thu, 2 Jul 2015 21:41:20 +0300 Subject: flowtop man: Add note about activating netfilter connection tracking Add the same note about using iptables to activate conntrack as it is already described in 'flowtop -h', just to keep it in the man page too. Signed-off-by: Vadim Kochan Signed-off-by: Tobias Klauser --- flowtop.8 | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) (limited to 'flowtop.8') diff --git a/flowtop.8 b/flowtop.8 index 761f4a7..c850f12 100644 --- a/flowtop.8 +++ b/flowtop.8 @@ -37,7 +37,15 @@ The following information will be presented in flowtop's output: * Transport protocol state machine information .PP In order for flowtop to work, netfilter must be active and running -on your machine, thus kernel-side connection tracking is active. +on your machine, thus kernel-side connection tracking is active. If netfilter +is not running, you can activate it with iptables(8): +.in +4 +.sp +iptables -A INPUT -p tcp -m state --state ESTABLISHED -j ACCEPT +.sp +iptables -A OUTPUT -p tcp -m state --state NEW,ESTABLISHED -j ACCEPT +.in -4 + .PP flowtop's intention is just to get a quick look over your active connections. If you want logging support, have a look at netfilter's conntrack(8) tools @@ -125,7 +133,8 @@ Borkmann . .BR ifpps (8), .BR bpfc (8), .BR astraceroute (8), -.BR curvetun (8) +.BR curvetun (8), +.BR iptables (8) .PP .SH AUTHOR Manpage was written by Daniel Borkmann. -- cgit v1.2.3-54-g00ecf