Re: Too many connections and init_conntrack

2002-04-19 Thread Ankit Jain
--- Henrik Nordstrom <[EMAIL PROTECTED]> wrote: > Ankit Jain wrote: > > > Today we create a connection tracking entry for every > > new packet that we see, whether valid, invalid or > > even for one that will be dropped in future by filter. > > > > Is

Too many connections and init_conntrack

2002-04-18 Thread Ankit Jain
Hi All, Today we create a connection tracking entry for every new packet that we see, whether valid, invalid or even for one that will be dropped in future by filter. Is there an advantage in this design approach? Does it make sense not to create these entries so that an intruder is not able to