As of Linux kernel 5.0, nf_nat_proto_gre is gone and nf_conntrack_proto_gre is built-in to the kernel (no longer a module). Consequently, trying to disable the GRE conntack module fails:
vyos@vyos:~$ configure [edit] vyos@vyos# set system conntrack modules pptp disable [edit] vyos@vyos# set system conntrack modules gre disable [edit] vyos@vyos# commit [ system conntrack hash-size 32768 ] Updated conntrack hash size. This change will take affect when the system is rebooted. [ system conntrack modules gre disable ] rmmod: ERROR: Module nf_nat_proto_gre is not currently loaded rmmod: ERROR: Module nf_conntrack_proto_gre is not currently loaded [[system conntrack]] failed Commit failed [edit] vyos@vyos# exit discard exit vyos@vyos:~$ show version Version: VyOS 1.3-beta-202102040443 Release Train: equuleus Built by: [email protected] Built on: Thu 04 Feb 2021 04:43 UTC Build UUID: d3d7fa63-efaf-435f-9d02-a171a8ecf96b Build Commit ID: e5b0cc71295acd Architecture: x86_64 Boot via: installed image System type: KVM guest Hardware vendor: QEMU Hardware model: Standard PC (Q35 + ICH9, 2009) Hardware S/N: Hardware UUID: d0204c55-cfc3-47a0-bc5b-459efcb76ba8 Copyright: VyOS maintainers and contributors
As it is no longer possible to disable GRE connection tracking at runtime, the configuration node should be removed.