From mboxrd@z Thu Jan 1 00:00:00 1970 From: Tobias DiPasquale Subject: Re: deleting a conntrack record Date: Thu, 17 Jun 2004 11:31:04 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <876ef97a040617083152c643b4@mail.gmail.com> References: <876ef97a0406170807663b89e0@mail.gmail.com> <200406171620.24232.Antony@Soft-Solutions.co.uk> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <200406171620.24232.Antony@Soft-Solutions.co.uk> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter On Thu, 17 Jun 2004 16:20:23 +0100, Antony Stone wrote: > Why not just use the built-in timeouts to delete stale entries from the > conntrack table? > > You can adjust the timeout settings using entries in > /proc/sys/net/ipv4/netfilter and I believe there may be a p-o-m update to > give even further fine-grained control. Because I only want to delete conntrack records for certain connections, so timing out all TCP connections early is no good. As well, I can't just do that alone also because other operations have to be performed aside from deleting the conntrack record. -- [ Tobias DiPasquale ] 0x636f6465736c696e67657240676d61696c2e636f6d