Hi Patrick, Here it follows a patch that I've been using in my testbed for some time to improve the recovery of out-of-sync TCP flows. You can pull this patch from: git://1984.lsi.us.es/nf-next-2.6 master --- Pablo Neira Ayuso (1): netfilter: conntrack: improve out-of-sync situation in TCP tracking include/linux/netfilter/nf_conntrack_tcp.h | 3 ++ net/netfilter/nf_conntrack_proto_tcp.c | 51 +++++++++++++++++++++++----- 2 files changed, 44 insertions(+), 10 deletions(-) -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html