On Mon, Sep 03, 2012 at 10:29:40PM -0700, Maciej Żenczykowski wrote: [...] > > Not solved: > > 4. Since NOTRACK now always maps to CT, "-j NOTRACK" > > has become unusable on sufficiently old kernels. > > Should we even bother? > > Yes, we must, otherwise distros can't upgrade to latest iptables > without either patching or upgrading kernel. Why not? They will upgrade and they will start using the CT target sooner than any other, which seems good to me. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html