On Fri, 8 Aug 2003, Joshua Banks wrote:
> Shorewall has detected the following iptables/netfilter capabilities:
> NAT: Available
> Packet Mangling: Available
> Multi-port Match: Available
> Connection Tracking Match: Not available
>
> Is "Connection Tracking Match: Not available" mean that stateful
inspection of packets isn''t
> happening?
>
>
No -- it means that you are running kernel 2.4.20 or earlier so you
don''t
have the new connection tracking match facility that''s in the 2.4.21
kernel. See the 1.4.6 enhancement list on the Shorewall home page.
-Tom
--
Tom Eastep \ Shorewall - iptables made easy
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net