I am using iptables for nat kernel version is 2.6.35+ working on powerpc target case 1) traffic is already flowing and we apply a rule, that rule will become effective only when we stop traffic and start again. case 2) traffic is already flowing and we delete a rule, this rule will still be effective unless we stop and start traffic again. observation: /proc/net/ip_conntrack file is updated only after stoping and starting traffic again. These two are the limitations i am facing. Is there a way to overcome these limitations. Please reply Thanks and Regards, Rahul Shrivastava -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html