Linux Netfilter discussions
 help / color / mirror / Atom feed
From: noa levy <levynoa@yahoo.com>
To: netfilter@vger.kernel.org
Subject: Dynamically adding rules - are connection tracking states maintained?
Date: Thu, 24 Apr 2008 09:12:29 -0700 (PDT)	[thread overview]
Message-ID: <989878.86998.qm@web57314.mail.re1.yahoo.com> (raw)

Hi All,

I'm trying to understand the impact of dynamically adding iptables rules, in terms of the resulting disruption to the firewall's performance. When I add a rule to (or delete a rule from) iptables, while it is running, does that have any effect on the states in the connection tracking table? Will the table be flushed? Are states linked to the rule that allowed the initial packet in, so that if a rule is deleted, only the corresponding state entry will be flushed?

Thank you!
Noa  


      ____________________________________________________________________________________
Be a better friend, newshound, and 
know-it-all with Yahoo! Mobile.  Try it now.  http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ


             reply	other threads:[~2008-04-24 16:12 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-04-24 16:12 noa levy [this message]
2008-04-24 19:24 ` Dynamically adding rules - are connection tracking states maintained? Pascal Hambourg
2008-04-25 17:39   ` Jan Engelhardt
  -- strict thread matches above, loose matches on Subject: below --
2008-04-28 22:27 noa levy
2008-04-29 23:37 ` Pascal Hambourg
2008-05-01 20:22   ` noa levy
2008-05-01 22:44     ` Josh Cepek
2008-05-01 22:56       ` Petr Pisar
2008-05-02  1:10       ` Pablo Neira Ayuso

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=989878.86998.qm@web57314.mail.re1.yahoo.com \
    --to=levynoa@yahoo.com \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox