connection tracking without iptables?

Alexis alexis at
Wed Sep 29 22:57:29 CEST 2004

Yes it is, is inside the code, i think this example could explain you

echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -P FORWARD DROP
iptables -A FORWARD -i $inside_interface -o $outside_interface -m state
--state NEW -j ACCEPT
iptables -A FORWARD -i $outside_interface -m state --state

That's it, this is what you need in order to get a statefull firewall with 2

> -----Mensaje original-----
> De: netfilter-bounces at 
> [mailto:netfilter-bounces at] En nombre de 
> Jiann-Ming Su
> Enviado el: Miércoles, 29 de Septiembre de 2004 17:51
> Para: netfilter at
> Asunto: connection tracking without iptables?
> This is probably a dumb question, but is it possible to track
> connections without iptables/netfilter?
> -- 
> Jiann-Ming Su
> "I have to decide between two equally frightening options.  
>                                             If I wanted to do that,
> I'd vote." --Duckman

More information about the netfilter mailing list