Hi everybody, I'm currently playing around with stateful packet filtering/mangling and fragmented IPv4/IPv6 traffic. I was wondering if the conntrack timeouts for collecting all fragments of an IP packet are these values from sysctl: net.ipv4.ipfrag_time = 30 net.ipv6.ip6frag_time = 60 Or does it have separate timeouts somewhere else? Best regards Karsten Hohmeier -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html