Miscellaneous openVZ notes
From Notes_Wiki
Miscellaneous openVZ notes
Enabling iptables conntrack modules in container
By default iptables conntrack modules are not enabled for container. Hence 'state' module does not works properly within a container. To enable use of state module in container use:
vzctl set <CID> --iptables iptable_filter --iptables ip_conntrack --save
Note that this requires container to be stopped and then started again. Also base machine should have the connection tracking modules installed and preferably even in use through base machines firewall.