On Thursday 2010-05-13 19:08, Markus Feldmann wrote: > Hi All, > > i am still experiment with iptables and the state extension. Some of my rules > shall catch packets with the state NEW, but it doesn't catch all packets. > Sometimes there are packets that have the SYN Flag set which go through my > rules with the state NEW. > > Any idea why? Where's the ruleset? > I thought SYN is included in the state NEW, is that wrong? There are cases where SYN can be INVALID, naturally. Furthermore, CTs may be NEW even if the packet is not TCP SYN. > What is the difference between SYN and NEW? Kinda like the difference between "new" and "refurbished". -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html