netfilter: conntrack: remove ignore stats
This counter increments when nf_conntrack_in sees a packet that already has a conntrack attached or when the packet is marked as UNTRACKED. Neither is an error. The former is normal for loopback traffic. The second happens for certain ICMPv6 packets or when nftables/ip(6)tables rules are in place. In case someone needs to count UNTRACKED packets, or packets that are marked as untracked before conntrack_in this can be done with both nftables and ip(6)tables rules. Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:

committed by
Pablo Neira Ayuso

parent
b1328e54ac
commit
4afc41dfa5
@@ -247,7 +247,7 @@ enum ctattr_stats_cpu {
|
||||
CTA_STATS_FOUND,
|
||||
CTA_STATS_NEW, /* no longer used */
|
||||
CTA_STATS_INVALID,
|
||||
CTA_STATS_IGNORE,
|
||||
CTA_STATS_IGNORE, /* no longer used */
|
||||
CTA_STATS_DELETE, /* no longer used */
|
||||
CTA_STATS_DELETE_LIST, /* no longer used */
|
||||
CTA_STATS_INSERT,
|
||||
|
Reference in New Issue
Block a user