hi, it seems that once the ip_conntrack table is being filled up, the system will crash. Does it means that it is very vulnerable to DOS attack? I have performed a port scan using nmap on my box, and it is able to scan alot of ports being opened? How come this happened? I only allow established,related tcp packets and tcp port 22 New on INPUT to the box? The default policy is DROP. The result is port 22 open port 80 open Why it is so? Pls advise. Thanks in advanced. ben