Hi All, I'm trying to understand the impact of dynamically adding iptables rules, in terms of the resulting disruption to the firewall's performance. When I add a rule to (or delete a rule from) iptables, while it is running, does that have any effect on the states in the connection tracking table? Will the table be flushed? Are states linked to the rule that allowed the initial packet in, so that if a rule is deleted, only the corresponding state entry will be flushed? Thank you! Noa ____________________________________________________________________________________ Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now. http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html