From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from Chamillionaire.breakpoint.cc ([146.0.238.67]:40630 "EHLO Chamillionaire.breakpoint.cc" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S934289AbeCMPj2 (ORCPT ); Tue, 13 Mar 2018 11:39:28 -0400 Date: Tue, 13 Mar 2018 16:39:24 +0100 From: Florian Westphal To: David Miller Cc: fw@strlen.de, nbd@nbd.name, pablo@netfilter.org, netfilter-devel@vger.kernel.org, netdev@vger.kernel.org Subject: Re: [PATCH 00/30] Netfilter/IPVS updates for net-next Message-ID: <20180313153924.GE31828@breakpoint.cc> References: <4521f7bd-c63a-9d2d-bdb3-5f4db58a7ba1@nbd.name> <20180312.160119.1610465393660409111.davem@davemloft.net> <20180313134139.GD31828@breakpoint.cc> <20180313.113434.1173466843045633114.davem@davemloft.net> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20180313.113434.1173466843045633114.davem@davemloft.net> Sender: netdev-owner@vger.kernel.org List-ID: David Miller wrote: [ flow tables ] > Ok, that seems to constrain the exposure. > > We should talk at some point about how exposed conntrack itself is. Sure, we can do that. If you have specific scenarios (synflood, peer that opens 100k (legitimate) connections, perpetual-fin, etc) in mind let me know, i do think that we could still do better in some cases.