Jozsef Kadlecsik wrote: > Then the best were if you could capture a full TCP session by > tcpdump and send it so that we could replay and analyze the traffic. I've uploaded an archive to http://baetzler.de/sandbox/dump.tar.bz2. There is a complete tcp session of a file upload and a second dump that contains a segment from that connection that was IMHO erroneously logged/dropped by a rule that filters by state INVALID in the PREROUTING chain of the mangle table. Inititator is my NAT box, target is the FTP server. TIA, Thomas -- BRINGE Informationstechnik GmbH Zur Seeplatte 12 D-76228 Karlsruhe Germany Fon: +49 721 94246-0 Fon: +49 171 5438457 Fax: +49 721 94246-66 Web: http://www.bringe.de/ Geschäftsführer: Dipl.-Ing. (FH) Martin Bringe Ust.Id: DE812936645, HRB 108943 Mannheim -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html