From mboxrd@z Thu Jan 1 00:00:00 1970 From: Feizhou Subject: Re: Is this firewall good enough? Date: Wed, 09 Jun 2004 21:23:50 +0800 Sender: netfilter-admin@lists.netfilter.org Message-ID: <40C70F66.4080907@linuxmail.org> References: Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii"; format="flowed" To: Jozsef Kadlecsik Cc: David Cannings , netfilter@lists.netfilter.org > - Use raw table and NOTRACK to skip conntrack for the (UDP) DNS queries > and still benefit from conntrack for all other connections. > pom raw patch. Testing....ouch, bit on the edge for me to try to use that... I'd love to be able to track nothing but smtp and optimize on that too so that I can give connlimit a go.