On Wednesday 23 June 2004 5:01 pm, Tobias DiPasquale wrote: > Hi all, > > Is there a way to get conntrack to _not_ track UDP connections (or > also ICMP)? It seems rather pointless to me and its certainly taking > up way too much memory on my box just for some DNS queries. Any ideas? This may help: http://lists.netfilter.org/pipermail/netfilter/2003-October/047892.html Regards, Antony. -- Perfection in design is achieved not when there is nothing left to add, but rather when there is nothing left to take away. - Antoine de Saint-Exupery Please reply to the list; please don't CC me.