netfilter.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* nf-ct-list and nf-exp-delete
@ 2025-10-07  9:15 imnozi
  2025-10-07 11:10 ` Pablo Neira Ayuso
  0 siblings, 1 reply; 5+ messages in thread
From: imnozi @ 2025-10-07  9:15 UTC (permalink / raw)
  To: netfilter

[iptables v1.8.7; old, but it's what I have.]

Why does 'nf-exp-delete -i [id]' *not* remove remove some conntrack entries even after being told to remove them multiple times? It deletes most entries for my purposes (if condition is met, delete conntrack entry and block the IP using ipset). Blocked IPs are DROPped on internet side, and RESET and REJECTed on the internal side. But from time to time, I see ESTABLISHED conns that don't get (can't be) deleted.

Thanks,
Neal

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2025-10-08 21:01 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-10-07  9:15 nf-ct-list and nf-exp-delete imnozi
2025-10-07 11:10 ` Pablo Neira Ayuso
2025-10-07 22:45   ` imnozi
2025-10-08 11:50     ` Pablo Neira Ayuso
2025-10-08 21:01       ` imnozi

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).