From: Benedikt Gollatz <ben@differentialschokolade.org>
To: "David Balažic" <xerces9@gmail.com>
Cc: netfilter@vger.kernel.org
Subject: Re: Problem with IPv6 tunnel
Date: Fri, 19 Jun 2009 14:13:43 +0200 [thread overview]
Message-ID: <200906191413.43513.ben@differentialschokolade.org> (raw)
In-Reply-To: <9948385e0906190503i223f715s49730aa8e5e5df89@mail.gmail.com>
On Friday 19 June 2009, 14:03 David Balažic wrote:
> One more thing: Where is the timeout for this set ?
/proc/sys/net/netfilter/nf_conntrack_generic_timeout I presume.
> After the mentioned ping, the world can contact me for hours.
That's much too long for the default setting of a timeout. AFAIK the heartbeat
client must send keepalive packets every 300 seconds so the tunnel and
connection tracking timeouts may influence each other.
> I want to lower the timeout to a minute or so, so I can test the
> setting without the need to wait hours for the timeout to happen.
Why do you want to conntrack proto-41 packets at all? If you're worried about
security, filter the IPv6 traffic using ip6tables.
Benedikt
next prev parent reply other threads:[~2009-06-19 12:13 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-06-19 8:31 Problem with IPv6 tunnel David Balažic
2009-06-19 10:18 ` Benedikt Gollatz
2009-06-19 12:03 ` David Balažic
2009-06-19 12:13 ` Benedikt Gollatz [this message]
2009-06-19 12:57 ` David Balažic
2009-06-19 13:08 ` Benedikt Gollatz
2009-06-19 13:37 ` David Balažic
2009-06-21 13:44 ` Chris Hills
2009-06-21 13:46 ` Chris Hills
2009-07-09 15:30 ` Pascal Hambourg
2009-06-19 10:18 ` Benedikt Gollatz
2009-07-09 11:48 ` David Balažic
2009-07-09 13:06 ` David Balažic
2009-07-09 14:51 ` Benedikt Gollatz
2009-07-09 15:34 ` Pascal Hambourg
2009-07-10 11:50 ` Benedikt Gollatz
2009-07-10 13:40 ` Pascal Hambourg
2009-07-10 15:00 ` David Balažic
2009-07-10 15:30 ` Pascal Hambourg
2009-07-10 22:31 ` David Balažic
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200906191413.43513.ben@differentialschokolade.org \
--to=ben@differentialschokolade.org \
--cc=netfilter@vger.kernel.org \
--cc=xerces9@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.