Just want to check with you on how much RAM do you have? What is the max table size (cat /proc/sys/net/ipv4/ip_conntrack_max) and if possible what is the size of the connection table before it crashes? I have the same problem too on kernel 2.4.18-xfs. What is yours? I believe the bug is called OOM (out-of-memory). .//Jet ----- Original Message ----- From: Ben Tan To: a Sent: Friday, November 01, 2002 6:44 PM Subject: does the ip_conntrack subjected to DOS attack??? hi, it seems that once the ip_conntrack table is being filled up, the system will crash. Does it means that it is very vulnerable to DOS attack? I have performed a port scan using nmap on my box, and it is able to scan alot of ports being opened? How come this happened? I only allow established,related tcp packets and tcp port 22 New on INPUT to the box? The default policy is DROP. The result is port 22 open port 80 open Why it is so? Pls advise. Thanks in advanced. ben