Disable nf_conntrack_helper, DMA error on WR1043ND v1

Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware
Author Message
jester322
DD-WRT Novice


Joined: 27 Jul 2021
Posts: 11

PostPosted: Tue Sep 14, 2021 11:10    Post subject: Disable nf_conntrack_helper, DMA error on WR1043ND v1 Reply with quote
Hi, DD-WRT community!
I have 2 questions regarding:

1. nf_conntrack_helper disabling:

echo 0 > /proc/sys/net/netfilter/nf_conntrack_helper

This command changes 1 to 0, but after sometime this value reverts to 1. I search for solution to turn it off without auto re-enabling. If this enabled, I get this message in dmesg:

nf_conntrack: automatic helper assignment is deprecated and it will be removed soon. Use the iptables CT target to attach helpers instead.

2. Also I get one more strange message in dmesg:

ath: phy0: DMA failed to stop in 10 ms AR_CR=0x00000024 AR_DIAG_SW=0x42100020 DMADBG_7=0x000286c1

What could be the reason for this message to appear and how to solve it? During this message I am experiencing connection issues.

Thanks in advance
Sponsor
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12875
Location: Netherlands

PostPosted: Tue Sep 14, 2021 11:37    Post subject: Reply with quote
We can give better support if you follow the forum guidelines: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087

Full of helpful pointers.

What build are you using?

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
jester322
DD-WRT Novice


Joined: 27 Jul 2021
Posts: 11

PostPosted: Tue Sep 14, 2021 14:21    Post subject: Reply with quote
I am using TP-Link WR1043ND v1 and build 3.10.108-dd #49299

Probably these issues are not directly related to DD-WRT, but Linux system services and ath9k driver, however there is some DD-WRT specifics I assume:
echo 0 > /proc/sys/net/netfilter/nf_conntrack_helper

This solution for disabling deprecated nf_conntrack_helper I found on Internet several times, but on DD-WRT something re-enables it.

As for ath9k DMA failed message - maybe someone struggled with this issue and has positive experience. The only thing I found - disable "Active Noise Immunity" - but this didn't help.
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14207
Location: Texas, USA

PostPosted: Tue Sep 14, 2021 14:31    Post subject: Re: Disable nf_conntrack_helper, DMA error on WR1043ND v1 Reply with quote
jester322 wrote:
nf_conntrack: automatic helper assignment is deprecated and it will be removed soon. Use the iptables CT target to attach helpers instead.

This message will stay there as netfilter cannot be disabled completely...

https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320586

jester322 wrote:
2. Also I get one more strange message in dmesg:

ath: phy0: DMA failed to stop in 10 ms AR_CR=0x00000024 AR_DIAG_SW=0x42100020 DMADBG_7=0x000286c1

What could be the reason for this message to appear and how to solve it? During this message I am experiencing connection issues.

Thanks in advance

This is likely a debug message and possibly nothing to be done about it.

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12875
Location: Netherlands

PostPosted: Tue Sep 14, 2021 14:57    Post subject: Reply with quote
jester322 wrote:
I am using TP-Link WR1043ND v1 and build 3.10.108-dd #49299

Probably these issues are not directly related to DD-WRT, but Linux system services and ath9k driver, however there is some DD-WRT specifics I assume:
echo 0 > /proc/sys/net/netfilter/nf_conntrack_helper

This solution for disabling deprecated nf_conntrack_helper I found on Internet several times, but on DD-WRT something re-enables it.

As for ath9k DMA failed message - maybe someone struggled with this issue and has positive experience. The only thing I found - disable "Active Noise Immunity" - but this didn't help.


The build number is more useful in this respect.
Recent builds have an Administration/Sysctl page take a look if this settings is available there.
If you can set it there it will stay.

If it is not available there set that rule in Administration/Commands and save as Firewall.

If the firewall restarts that rule will be applied again.

Not sure if this helps.

Out of curiosity are you disabling the conntrack helpers because of safety concerns?

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6435
Location: UK, London, just across the river..

PostPosted: Tue Sep 14, 2021 15:05    Post subject: Reply with quote
log in via Telnet/SSh

nvram show | grep nf_conntrack --- to find it as a value

than issue those commands:

nvram set nf_conntrack_helper=0
nvram commit

as the others said its a normal to have it in the syslog..so, nothing to be worried about, unless you have a very specific reason...bear in mind its a part of the netfilter functinality

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55779 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913


Last edited by Alozaros on Tue Sep 14, 2021 15:15; edited 2 times in total
d33b0_n4p41m
DD-WRT User


Joined: 10 Sep 2021
Posts: 133

PostPosted: Tue Sep 14, 2021 15:12    Post subject: Reply with quote
Doing that can break netfilter. That message is about netfilter kernel modules that are loaded on boot. It's like disabling the firewall on an edgerouter.
_________________
An old man said, “Erasers are made for those who make mistakes.” A youth replied, “Erasers are made for those who are willing to correct their mistakes!” Attitude matters! ~ Anonymous
----------
“You are always a student, never a master. You have to keep moving forward.” ~ Conrad Hall
----------
“Life is about moving on, accepting changes and looking forward to what makes you stronger and more complete.” ~ Anonymous
jester322
DD-WRT Novice


Joined: 27 Jul 2021
Posts: 11

PostPosted: Wed Sep 15, 2021 8:40    Post subject: Reply with quote
Thank you for responses. I searched for nf_conntrack* variables in nvram and there is none of them present. I supposed these nf_conntrack_helpers are primarily done for very specific protocols such as SIP, H.323 etc.

https://home.regit.org/netfilter-en/secure-use-of-helpers/

Assumption was if they use router resources which may lead to dmesg messages and probably connection issues, I thought to disable them. From your replies I understand that these helpers are needed to have firewall functionality, and most probably they have no performance impact.
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12875
Location: Netherlands

PostPosted: Wed Sep 15, 2021 9:26    Post subject: Reply with quote
If it is not on the syctl page it does not have an nvram variable (or at least an nvram variable does not work)

I do not think it has a performance impact so you should be good just leaving it as it is

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
d33b0_n4p41m
DD-WRT User


Joined: 10 Sep 2021
Posts: 133

PostPosted: Wed Sep 15, 2021 10:11    Post subject: Reply with quote
It's a Linux 3.x-specific warning that informs you of an upcoming change; it's a benign log message. No need to freak out about it.
_________________
An old man said, “Erasers are made for those who make mistakes.” A youth replied, “Erasers are made for those who are willing to correct their mistakes!” Attitude matters! ~ Anonymous
----------
“You are always a student, never a master. You have to keep moving forward.” ~ Conrad Hall
----------
“Life is about moving on, accepting changes and looking forward to what makes you stronger and more complete.” ~ Anonymous
mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 6285
Location: Texas

PostPosted: Wed Sep 15, 2021 12:11    Post subject: Reply with quote
d33b0_n4p41m wrote:
No need to freak out about it.

Laughing

https://forum.dd-wrt.com/phpBB2/viewtopic.php?p=1245439#1245439
last line in that bit of dmesg I've seen for very long time ...everytime / anytime I have the WNDR3700v4 setup in gateway mode as main
mrjcd wrote:

<6>[ 1928.070000] nf_conntrack: automatic helper assignment is deprecated and it will be removed soon. Use the iptables CT target to attach helpers instead.

I can assure you guys it ain't nothing to worry with.
AND
I don't see it on the EA8500 ...but that fat girl uses the k4.9 Twisted Evil
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum