All I know is we are supposed to use iptables recipies to protect our
computers, and when I use
# iptables -A b -m state --state ESTABLISHED,RELATED -j ACCEPT
in /var/log/syslog I see
nf_conntrack version 0.5.0 (8046 buckets, 32184 max)
CONFIG_NF_CT_ACCT is deprecated and will be removed soon. Please use
nf_conntrack.acct=1 kernel paramater, acct=1 nf_conntrack module option or
sysctl net.netfilter.nf_conntrack_acct=1 to enable it.
I read /usr/share/doc/iptables/README.Debian but that's over my head.