by the way, what does it count now? because earlier, when you use 'connection-limit', it counted ALL tcp connections, even if you set some limits, like 'dst-port=25'. so, if you now set 'protocol=tcp connection-limit=...', what will it count: only TCP connections, or all connections from that IP? I...