Hi, here is a new attempt of bringing in per-net functionality into nf conntrack protos. Please review and test if possible. It's quite far from ideal solution Alexey proposed (to try to shrink sysctl's manipulation in one place with all #ifdef guardians we need) but I didn't manage to implement it right way yet. So mostly at moment it looks like a code _bloat_ so rejecting this series would be acceptable solution :) ICMP v6 is not covered yet as well. Will be done. Cyrill -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html