From mboxrd@z Thu Jan 1 00:00:00 1970 From: Friedrich Lobenstock Subject: Re: question regarding iptables tuning (was Re: iptables denial of services) Date: Sat, 17 Apr 2004 22:18:37 +0200 Sender: netfilter-devel-admin@lists.netfilter.org Message-ID: <4081911D.1070307@fl.priv.at> References: <408167F2.9060501@fl.priv.at> <408180C7.6080302@eurodev.net> <40818C75.8010609@fl.priv.at> Reply-To: Netfilter Development Mailinglist Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Return-path: To: Netfilter Development Mailinglist In-Reply-To: <40818C75.8010609@fl.priv.at> Errors-To: netfilter-devel-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Unsubscribe: , List-Archive: List-Id: netfilter-devel.vger.kernel.org Friedrich Lobenstock wrote on 17.04.2004 21:58 MET: > Pablo Neira wrote on 17.04.2004 21:08 MET: > >> Hi Friedrich, >> >> Friedrich Lobenstock wrote: >> >>> Any suggestions for those parameters that are based on your experiences? >> >> >> >> maybe this could be interesting for you, it's related to conntrack >> system. >> >> http://www.wallfire.org/misc/netfilter_conntrack_perf.txt >> http://bei.bof.de/ >> >> I don't know how up to date they are, actually they are still in my >> queue of things to be read ;-). > > > BIG THANKS for the links! > > May I suggest to add the first link to the faq? > As the hash algorithm needs the hash size to be prime, here a link to find a fitting one http://www.prime-numbers.org/ which should be linked right after the above mentioned link. -- MfG / Regards Friedrich Lobenstock