could you please give an example of such related connection with dead parent?..
Well, I was once troubleshooting and noticed that although I changed a connection mark for a certain data stream the stream just kept on with the old mark.
This is what MT wrote to me after a consult:
"As long as your connection will stays in connection tracking table it will have that mark, even if those rules are disabled."
Same lately, to test connection marking and see what traffic really is in the conn.tracker I each time have to erase the whole list otherwise I just am looking at old markers mixed with new ones.
Some months ago I noticed that I could kill a P2P session only by erasing all connection tracker registers after I started to block some with a firewall filter. If I did not erase the connection in the tracker the connection came back each day, even if the client had its PC shut down or I shut his antenna down for him (disabled ether port). The next time he was switched back on the P2P stream started to run again because the http connection tracking time out was 24 hours or so. I set the timeout back to 1 hours and next day the client hang on the phone his P2P didn't work anymore!
For me proof enough that as long as a connection is in the connection tracker it CAN (not will!) be used by the same application again.
Ehh, thanks for pointing me to the ´edit´ button. Never seen that one!
