05.03.2011, 18:13, "Alex" <mysqlstudent@xxxxxxxxx>: > The last two are just regular requests for access to facebook from > another PC on the internal network. This packets can be out-of-order or duplicate packets with FIN flag. They are not connected to any conntrack entry, so there is no way to do NAT transformation for them. -- wbr, Oleg. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html