path: root/doc
diff options
authorPablo Neira Ayuso <>2011-02-22 16:05:09 +0100
committerPablo Neira Ayuso <>2011-02-22 16:05:09 +0100
commit553cd1fa98a2e3eb88c0f08e961de8ca4cda5de1 (patch)
tree5cb27ecc6584fd1a2c4fa73e540cb1aa6924d22b /doc
parentad17836eb03998236be259af2312c4a11b3e45f0 (diff)
doc: add reference to the CT target again
Now that we have fixed several aspects of the event filtering in 2.6.38, I reintroduce the documentation for this feature. Signed-off-by: Pablo Neira Ayuso <>
Diffstat (limited to 'doc')
1 files changed, 27 insertions, 0 deletions
diff --git a/doc/manual/conntrack-tools.tmpl b/doc/manual/conntrack-tools.tmpl
index 08b5b95..64cb91f 100644
--- a/doc/manual/conntrack-tools.tmpl
+++ b/doc/manual/conntrack-tools.tmpl
@@ -631,6 +631,33 @@ Sync {
+<sect3 id="sync-iptables-filtering">
+<title>Filtering Connection tracking events with iptables</title>
+ <para>Since Linux kernel &gt;= 2.6.34, iptables provides the
+ <emphasis>CT</emphasis> iptables target that allows to reduce the
+ amount of Connection Tracking events that are delivered to user-space.
+ However, you will have to use a Linux kernel &gt;= 2.6.38 to profit
+ from this feature, since several aspects of the event filtering were
+ broken.</para>
+ <para>The following example shows how to only generate the
+ <emphasis>assured</emphasis> event:</para>
+ <programlisting>
+ # iptables -I PREROUTING -t raw -j CT --ctevents assured
+ </programlisting>
+ <note><title>Assured flows</title>
+ <para>One flow is assured if the firewall has seen traffic for it in
+ both directions.</para>
+ </note>
+ <para>Reducing the amount of events generated helps to reduce CPU
+ consumption in the active firewall.</para>
<sect2 id="sync-trouble"><title>Troubleshooting</title>