[clue-tech] Making linux netfilter ip_conntrack forget an entry?

Kevin Fenzi kevin at scrye.com
Fri May 27 20:26:22 MDT 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

>>>>> "Jim" == Jim Ockers <ockers at ockers.net> writes:

Jim> Hi everyone, As you may know the Linux kernel's netfilter code
Jim> maintains a connection list in /proc/net/ip_conntrack (probably
Jim> the ip_conntrack.o kernel module does this).

Jim> ... ip_conntract description... 

Jim> Thanks for any ideas, Jim

I was looking for something like this a while ago, and pretty much the
only option I could find was to rmmod the ip_conntrack modules and
reload them. However, that will wipe ALL of the connection tracking
entries. 

If you come up with a way to remove a single entry I'd love to hear
how. ;) 

kevin
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)
Comment: Processed by Mailcrypt 3.5.8 <http://mailcrypt.sourceforge.net/>

iD8DBQFCl9bR3imCezTjY0ERAlmhAJ0VCPaPQP7P4UNqilD4vye/cpFwiwCghS2+
I/nFK95ixcxGV6i3nNzBTwc=
=9Fj+
-----END PGP SIGNATURE-----



More information about the clue-tech mailing list