Hi Patrick, This is one bugfix for the iptables' CT event filtering. There's one situation in which the filtering does not work for TCP flows. See patch description for details, please apply! Thanks! --- Pablo Neira Ayuso (1): netfilter: nf_conntrack: set conntrack templates again if we return NF_REPEAT net/netfilter/nf_conntrack_core.c | 11 +++++++++-- 1 files changed, 9 insertions(+), 2 deletions(-) -- tum-te-tum-dum-de-dum -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html