[NF_CONNTRACK] first conntrack ID must be 1 not 2 The first conntrack ID must be 1. If a new conntrack is created, the general ID counter must be post-incremented instead pre-incremented since [ip|nf]_conntrack_next_id is initialized to 1. Same applies for expectations. Signed-off-by: Pablo Neira Ayuso -- The dawn of the fourth age of Linux firewalling is coming; a time of great struggle and heroic deeds -- J.Kadlecsik got inspired by J.Morris