On Friday 15 October 2004 00:27, Jason Opperisano wrote: > i'm not aware of any way that reading /proc/net/ip_conntrack would > prevent the system from creating new conntrack entries, but there's lots > of things that i'm not aware of... AFAIR, the proc interface for the ip conntrack contents was considered broken and was moved to use the seq_file interface. The patch to this effect went into 2.6.9-rc1. http://lists.netfilter.org/pipermail/netfilter-devel/2004-July/016149.html I am not sure, but may be this patch could help you. -- Regards, Kiran Kumar Immidi