On Thu, 20 Mar 2003, [iso-8859-1] Leonardo Rodrigues Magalhăes wrote: > I got a firewall running kernel 2.4.20 with some p-o-m patches, > including tcp-window-tracking which allows me change timeout stuff in > runtime. > > Well ...... my /proc/net/ip_conntrack log is PLENTY of CLOSE > connections, just like: This is a bug in 2.4.20. You need the submitted/10_confirm_fix.patch.help patch from the most recent patch-o-matic. Regards, Jozsef - E-mail : kadlec@xxxxxxxxxxxxxxxxx, kadlec@xxxxxxxxxxxxxxx PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt Address : KFKI Research Institute for Particle and Nuclear Physics H-1525 Budapest 114, POB. 49, Hungary