Re: ip_conntrack

In article <20040210134500.GA22460@klub.org> rory@klub.org writes:
>On Tue, Feb 10, 2004 at 01:12:37PM, Bjoern Schmidt wrote:
>> It is possible to clear all ore one entries in /proc/net/ip_conntrack
>> without a reboot? I know there is a timeout, but i would like to remove
>> them immediately if needed.

>As far as I'm aware, you can remove all, but not just one. If you
>/really/ need to do that, you're going to need to investigate sending
>spoofed RST packets, which can get rather hairy...

For tcp connections, you can use the cutter command (in the package of
the same name) to send the RST packets.  I just got a bug report about
it with a 2.6 kernel, so it may only work with 2.4 kernels for now.
Backporting to woody is a simple recompile.
Blars Blarson			blarson@blars.org
With Microsoft, failure is not an option.  It is a standard feature.

