All of lore.kernel.org
 help / color / mirror / Atom feed
* ip_conntrack_max
@ 2004-07-08  9:38 Fallucchi Antonio
  2004-07-08  9:56 ` ip_conntrack_max Antony Stone
  2004-07-08  9:56 ` ip_conntrack_max Evgeni Vachkov
  0 siblings, 2 replies; 13+ messages in thread
From: Fallucchi Antonio @ 2004-07-08  9:38 UTC (permalink / raw)
  To: netfilter

hi

i have the problem width "ip_conntrack: table full, dropping packet."

what is the good and max dimension  of the ip_conntrack_max ?

tanks.
bye


^ permalink raw reply	[flat|nested] 13+ messages in thread
* ip_conntrack_max
@ 2004-07-08  9:34 Fallucchi Antonio
  0 siblings, 0 replies; 13+ messages in thread
From: Fallucchi Antonio @ 2004-07-08  9:34 UTC (permalink / raw)
  To: netfilter

hi

i have the problem width "ip_conntrack: table full, dropping packet."

what is the good and max dimension  of the ip_conntrack_max ?

tanks.
bye

-- 

 ---------------------------------------------------------------
| |||||||    ||    |  Fallucchi Antonio Giuseppe  mat. 2282     |
| ||        ||||    |      --> Live free() of die() <--         |
| ||||     ||  ||    |        OpenSource philisophy             |
| ||      ||||||||    |  Universita' di Bologna sede di Cesena  |
| ||     ||      ||    |    Cdl di Scienze dell'Informazione    |
 ---------------------------------------------------------------




^ permalink raw reply	[flat|nested] 13+ messages in thread
* ip_conntrack_max
@ 2003-02-13 19:04 homsher
  0 siblings, 0 replies; 13+ messages in thread
From: homsher @ 2003-02-13 19:04 UTC (permalink / raw)
  To: netfilter

Hi everyone,

I hope this is an easy question for someone...

I upgraded my memory to 1.3 GB and my ip_conntrack_max increased to 65536 (from 16,xxx). Does this seem sufficient for a 50+ network? I've noticed that ip_conntrack tends to 'hang onto' connections when the remote client terminates abrubtly. For example, an incoming ssh connection on which the ssh client is rebooted may stay in ip_conntrack for 15 minutes or more -- I'm watching this now and it's been 20 minutes. The ssh client machine got M$ blue-screen-o-death and my iptables firewall hasn't figured out that the connection is gone. 

My question(s) are: Is it normal for conntrack entries to hang around after the remote connection has terminated ungracefully? If so, should the state table be 'cleaned up' periodically (and how is this done)? 

And, what happens if/when the firewall exceeds the 65536 connection limit?

Thanks to anyone who can enlighten me on this!

Lori



^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2004-07-08 17:42 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-07-08  9:38 ip_conntrack_max Fallucchi Antonio
2004-07-08  9:56 ` ip_conntrack_max Antony Stone
2004-07-08 10:31   ` ip_conntrack_max Fallucchi Antonio
2004-07-08 10:52     ` ip_conntrack_max Antony Stone
2004-07-08 13:13       ` ip_conntrack_max Fallucchi Antonio
2004-07-08 13:29         ` ip_conntrack_max Antony Stone
2004-07-08 17:02           ` ip_conntrack_max Fallucchi Antonio
2004-07-08 17:21           ` ip_conntrack_max Fallucchi Antonio
2004-07-08 17:42             ` ip_conntrack_max Antony Stone
2004-07-08 15:28         ` ip_conntrack_max James Sneeringer
2004-07-08  9:56 ` ip_conntrack_max Evgeni Vachkov
  -- strict thread matches above, loose matches on Subject: below --
2004-07-08  9:34 ip_conntrack_max Fallucchi Antonio
2003-02-13 19:04 ip_conntrack_max homsher

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.