Mandi! Rick Jones In chel di` si favelave... > Does it? I would think that the NAT/firewall would be maintaining > only the state needed to perform the address translations, leaving > the congestion avoidance (and response to the likes of say an ICMP > Destination Unreachable, Fragmentation Needed and DF set) to the > "actual" TCP endpoint. Ok, good to know. So, practically speaking, at least for TCP connection, it is better to ALWAYS ''open'' ICMP packets alongside TCP packets. Right? -- dott. Marco Gaiarin GNUPG Key ID: 240A3D66 Associazione ``La Nostra Famiglia'' http://www.sv.lnf.it/ Polo FVG - Via della Bontà, 7 - 33078 - San Vito al Tagliamento (PN) marco.gaiarin(at)lanostrafamiglia.it t +39-0434-842711 f +39-0434-842797 Dona il 5 PER MILLE a LA NOSTRA FAMIGLIA! http://www.lanostrafamiglia.it/25/index.php/component/k2/item/123 (cf 00307430132, categoria ONLUS oppure RICERCA SANITARIA) -- To unsubscribe from this list: send the line "unsubscribe lartc" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html