What is the option "nf_conntrack_tcp_be_liberal" for?

Solution Verified - Updated -

Issue

  • What is the option nf_conntrack_tcp_be_liberal?
  • RHEL sometimes drops SYN+ACK packet from new TCP connection handshake

Environment

  • Red Hat Enterprise Linux
  • NetFilter connection tracking firewall (conntrack) via iptables or nftables

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In