From mboxrd@z Thu Jan 1 00:00:00 1970 From: "=?ISO-8859-1?Q?Kerry_=D3_Cuanach=E1in?=" Subject: Notification of new/destroyed connection Date: Thu, 12 Jul 2007 10:13:53 +0100 Message-ID: Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit To: netfilter-devel@lists.netfilter.org Return-path: Content-Disposition: inline List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-devel-bounces@lists.netfilter.org Errors-To: netfilter-devel-bounces@lists.netfilter.org List-Id: netfilter-devel.vger.kernel.org Following on from the discussion on CT lifecycle events, if one takes a scenario whereby a newly created connection is subsequently NF_DROP'd by a filter rule, is it exclusively a timer/timeout which results in that same connection being destroyed? Is there any event driven mechanism to inform conntrack that the packet has been filtered? Similarly, is there an way to identify the reason for IPCT_DESTROY from the event raised? Kind Regards Kerry