On Friday 18 April 2008 13:43:25 Jason Stubbs wrote: > I would think that behaviour to be correct, but an entry appearing when > only an ACK packet has been sent seems wrong. Is it a bug or intentional? It seems it's intentional. After a bit more searching I finally found out about the net.netfilter.nf_conntrack_tcp_loose sysctl setting. Is this setting (and the others) documented anywhere other than the source? -- Jason Stubbs <j.stubbs@xxxxxxxxxxxxxxx> LINKTHINK INC. 東京都渋谷区桜ヶ丘町22-14 N.E.S S棟 3F TEL 03-5728-4772 FAX 03-5728-4773 -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html