ip_conntrack growing indefinitely
Eric Leblond
eric at inl.fr
Sat Aug 11 10:04:28 CEST 2007
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
Le Sat, 11 Aug 2007 09:38:08 +0200,
fd4 <fd4 at itsec4u.de> a écrit :
> > For now it has been patched setting ip_conntrack_max to 65536 but
>
> well :- on my wish list now something like that:
> conntrack -D -s 1.2.3.4 -d 1.2.3.4 -p tcp --orig-port-src 42573
> --orig-port-dst *
You should try this:
http://software.inl.fr/trac/trac.cgi/wiki/pynetfilter_conntrack
It does exactly what you want.
BR,
- --
Eric Leblond <eric at regit.org>
NuFW, Now User Filtering Works : http://www.nufw.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGvW2PnxA7CdMWjzIRAn4xAJsFD/7db/FCNw6iwTByznnY5PDpdACfdegE
pslZiNpAY6TtqT0F0Iw4HTw=
=6G59
-----END PGP SIGNATURE-----
More information about the netfilter
mailing list