On 30 July 2010 11:41, Michele Petrazzo - Unipex <michele.petrazzo@xxxxxxxxx> wrote: > > > A doubt. > Like said, INVALID is only a CT classification of my firewall. But, > since it's not a standard, how I can receive and reply (through my > FORWARD chain) to an INVALID packet? Who generate/classify it like > INVALID? My sender (I don't believe since it's not a standard) or my CT? > Your connection tracker... -- Richard Horton Users are like a virus: Each causing a thousand tiny crises until the host finally dies. http://www.pbase.com/arimus - My online photogallery http://www.richardhorton.info -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html