Re: ip_conntrack
In article <[🔎] 20040210134500.GA22460@klub.org> rory@klub.org writes:
>On Tue, Feb 10, 2004 at 01:12:37PM, Bjoern Schmidt wrote:
>> It is possible to clear all ore one entries in /proc/net/ip_conntrack
>> without a reboot? I know there is a timeout, but i would like to remove
>> them immediately if needed.
>As far as I'm aware, you can remove all, but not just one. If you
>/really/ need to do that, you're going to need to investigate sending
>spoofed RST packets, which can get rather hairy...
For tcp connections, you can use the cutter command (in the package of
the same name) to send the RST packets. I just got a bug report about
it with a 2.6 kernel, so it may only work with 2.4 kernels for now.
Backporting to woody is a simple recompile.
--
Blars Blarson blarson@blars.org
http://www.blars.org/blars.html
With Microsoft, failure is not an option. It is a standard feature.
Reply to: