On Monday 2010-11-01 20:06, "Oleg A. Arkhangelsky" wrote: >Hello, > >Maybe I'm wrong, but the last line of icmp_error_message() from >net/ipv4/netfilter/nf_conntrack_proto_icmp.c seems illogical to me. >Should it be return NF_ACCEPT, instead of -NF_ACCEPT? (Same with icmpv6.c) Hmm! Maybe that explains why the ICMPv6 packets from my HE tunnel are all -m conntrack --ctstate INVALID? (Ref.: http://www.spinics.net/lists/netfilter-devel/msg13247.html ) -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html