On Mon, 17 Jan 2005 07:38:54 +0800, Vincent <cs83152@xxxxxxxxxxxxxxx> wrote: > If I build the iptables connection tracking into kernel. How can I flush > the connection state clean. Without ctnetlink from patch-o-matic in the kernel, you can't. Install ctnetlink from patch-o-matic and you will be able to write a program that can delete individual conntrack records with netlink messages. -- [ Tobias DiPasquale ] 0x636f6465736c696e67657240676d61696c2e636f6d