From: Andy Smith <andy@strugglers.net>
To: netfilter@lists.netfilter.org
Subject: Re: Why does this connection stop being tracked?
Date: Wed, 15 Jun 2005 16:10:55 +0000 [thread overview]
Message-ID: <20050615161055.GT754@strugglers.net> (raw)
In-Reply-To: <Pine.LNX.4.60.0506151154340.25078@darkstar.sysinfo.com>
[-- Attachment #1: Type: text/plain, Size: 1314 bytes --]
On Wed, Jun 15, 2005 at 12:07:52PM -0400, R. DuFresne wrote:
> >> You have two choices: either disable TCP SACK support on all your
> >> real/virtual machines behind your firewall, or upgrade the kernel on the
> >> firewall.
> >
> > Do you have any instructions or a pointer to documentation onhow to
> > temporarily disable SACK? If it was a /proc setting that would be
> > ideal; I don't really want to have to recompile kernels though.
> >
>
> why? you are certainly missing out on how to fix and patch a systems when
> bugs in the kernel affect it, to the ability to add features that your
> dist maintainer has not enabled by default, or to change params in the
> kernel such as moving away or to kernel modules as opposed to stack
> functionality mapping.
I'm sorry, I didn't phrase that very well. I'm perfectly happy to
compile new kernels and indeed I am required to run a patched 2.6.11
plus some other patches that I have to apply manually in order to
use Xen.
$ uname -a
Linux curacao.strugglers.net 2.6.11curacaoxen0-steven-hand1 #1 Sat Jun 4 18:49:26 UTC 2005 i686 GNU/Linux
I just didn't want to make a new kernel and reboot in order to test
the suggestion of disabling SACK as the downtime of a reboot on a
machine with multiple virtual machines is unpopular.
[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
next prev parent reply other threads:[~2005-06-15 16:10 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-06-14 16:11 Why does this connection stop being tracked? Andy Smith
2005-06-15 11:18 ` Jozsef Kadlecsik
2005-06-15 11:30 ` Andy Smith
2005-06-15 11:47 ` Jozsef Kadlecsik
2005-06-15 16:07 ` R. DuFresne
2005-06-15 16:10 ` Andy Smith [this message]
2005-06-15 16:24 ` R. DuFresne
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20050615161055.GT754@strugglers.net \
--to=andy@strugglers.net \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.