Good morning,

just wondering if the behavior i discovered yesterday on our iptables-
firewall is "ok":

I connect from Box A via SSH to Box B, where the firewall runs, and i
get the state "NEW" on the first packet.
Then - the first connection is still established - i connect AGAIN from
Box A to Box B and do NOT get the state "NEW" anymore. (So obviously
it's already accepted by the ESTABLISHED,RELATED -j ACCEPT rule).
Is this behavior correct?

Meaning that a (second, third, ...) connection to the firewall will 
never get the state "NEW" for the first packet when there IS already
a connection to the same port, from the same host?

        
                regards, Chris


Reply via email to