Hi list, It is needed to do '-j NOTRACK' in order to avoid conntracking for some packets, or i can simply DROP packets on the raw table so they do not reach other netfilter tables and so it is not conntracking for those packets..? Now and simply do *raw -A PREROUTING <some criteria> -j DROP do i need to do -A PREROUTING <some criteria> -j NOTRACK -A PREROUTING <some criteria> -j DROP Thanks... -- --------------------------------------------- Clister UAH ---------------------------------------------