Index: linux-2.6.37/net/netfilter/nf_conntrack_proto_tcp.c =================================================================== --- linux-2.6.37.orig/net/netfilter/nf_conntrack_proto_tcp.c 2011-02-26 20:14:44.000000000 +0000 +++ linux-2.6.37/net/netfilter/nf_conntrack_proto_tcp.c 2011-02-26 20:15:03.000000000 +0000 @@ -227,11 +227,11 @@ * sCL -> sIV */ /* sNO, sSS, sSR, sES, sFW, sCW, sLA, sTW, sCL, sS2 */ -/*synack*/ { sIV, sSR, sSR, sIG, sIG, sIG, sIG, sIG, sIG, sSR }, +/*synack*/ { sIV, sSR, sIG, sIG, sIG, sIG, sIG, sIG, sIG, sSR }, /* * sSS -> sSR Standard open. * sS2 -> sSR Simultaneous open - * sSR -> sSR Retransmitted SYN/ACK. + * sSR -> sIG Retransmitted SYN/ACK, ignore it. * sES -> sIG Late retransmitted SYN/ACK? * sFW -> sIG Might be SYN/ACK answering ignored SYN * sCW -> sIG