All of lore.kernel.org
 help / color / mirror / Atom feed
* 2.4 kernels and max # of rules with iptables
@ 2005-06-20  2:07 Jason Wever
  2005-06-20  2:20 ` David S. Miller
                   ` (9 more replies)
  0 siblings, 10 replies; 11+ messages in thread
From: Jason Wever @ 2005-06-20  2:07 UTC (permalink / raw)
  To: sparclinux

[-- Attachment #1: Type: text/plain, Size: 824 bytes --]

Hi All,

I don't know if anyone else has run into this or not, but over in Gentoo
we've had a user report[1] of a "hard limit" as to the number of rules
you can have with iptables on the 2.4 kernels before it starts erroring
out. Currently, it seems that the limit is 857 rules, and the error
given is "iptables: Memory allocation problem".

I've been able to confirm this behavior on 2.4.31 (using
iptables 1.2.11 and 1.3.1) and was able to load more than 10,000 rules
in 2.6.12-rc3 before I gave up.

Current Gentoo userland is using either kernel headers from 2.4.23 (for
stable keywords) and 2.4.26 (for testing keywords).

If anyone has any suggestions or pointers, I'd be glad to hear them.

[1] - https://bugs.gentoo.org/show_bug.cgi?id=75668

Thanks,
-- 
Jason Wever
Gentoo/Sparc Team Co-Lead

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2005-08-22 17:17 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-06-20  2:07 2.4 kernels and max # of rules with iptables Jason Wever
2005-06-20  2:20 ` David S. Miller
2005-06-20  2:27 ` Jason Wever
2005-06-22  2:25 ` Jason Wever
2005-08-17 13:06 ` Josh Grebe
2005-08-17 18:33 ` David S. Miller
2005-08-17 18:53 ` Josh Grebe
2005-08-17 18:57 ` David S. Miller
2005-08-22 17:10 ` Gustavo Zacarias
2005-08-22 17:14 ` David S. Miller
2005-08-22 17:17 ` Gustavo Zacarias

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.