Linux Netfilter discussions
 help / color / mirror / Atom feed
* Getting rid of the masses of ip_conntrack messages
@ 2002-12-01 19:07 hard__ware
  2002-12-01 20:13 ` Othmar Pasteka
  0 siblings, 1 reply; 8+ messages in thread
From: hard__ware @ 2002-12-01 19:07 UTC (permalink / raw)
  To: netfilter

Please try to give a more detailed info on your setup

like Rules ect . Because i use DNAT / SNAT / with FTP
and  ip_conntrack_ftp & ip_nat_ftp  allot with IPTables
and have never found / seen those messages ? 

maybee thats cuz i dont log much anymore ..

i just drop / reject a Shitload  .. .lol 

let me know how ya go ... 

cyas,
 
Hard__warE


^ permalink raw reply	[flat|nested] 8+ messages in thread
* Getting rid of the masses of ip_conntrack messages
@ 2002-12-01 23:22 hard__ware
  0 siblings, 0 replies; 8+ messages in thread
From: hard__ware @ 2002-12-01 23:22 UTC (permalink / raw)
  To: Othmar Pasteka; +Cc: netfilter

have you made sure that the ip_conntrack_ftp module is loaded as well , #>
lsmod

If so the only thing i can suggest is disableing DROP on
your output for a while and remove the output rules.
(set its CHAIN to default of ACCEPT)

did this stop the messages ? other than that im not sure .
ive tried to follow the entire Kernel Source .c kode,
and to me it looks like you may have a problem in your output and maybe
contrack_ftp problems ...

cya...


^ permalink raw reply	[flat|nested] 8+ messages in thread
* Getting rid of the masses of ip_conntrack messages
@ 2002-12-01 21:46 hard__ware
  0 siblings, 0 replies; 8+ messages in thread
From: hard__ware @ 2002-12-01 21:46 UTC (permalink / raw)
  To: netfilter; +Cc: pasteka

I will get a new email / domain when i can afford it ..

anyway...

Ok now you have me sort of confused i thought you had
a Nefilter Gateway ? or maybee you do ? .


So all you really want is a Linux / GNU box setup as a FTP Server for the
Inetrnet /w DoS protection ect , ect.

If this is the case how is this box connected ?

you did say a Default Route existed this could be a gateway on your lan or
the ISP's gateway assigned to
you via DHCP on a WAN Device directly connected to
the Linux FTP box ..


^ permalink raw reply	[flat|nested] 8+ messages in thread
* Getting rid of the masses of ip_conntrack messages
@ 2002-12-01 10:04 Othmar Pasteka
  2002-12-01 20:33 ` Rob Sterenborg
  0 siblings, 1 reply; 8+ messages in thread
From: Othmar Pasteka @ 2002-12-01 10:04 UTC (permalink / raw)
  To: netfilter

Hello,

I get quite many "ip_conntrack: max number of expected connections 1
of ftp reached for 1.2.3.4->4.3.2.1, reusing" messages. How can I
configure netfilter that he doesn'T show such messages at all?
I am not interested in it and actually don't need/care about
them.
So far i googled a bit but just found that someone else had that
as well, but didn't find an answer :(. Answers are greatly
appreciated.

iptables: 1.2.6a
kernel: 2.4.20

anything else what's needed?

TIA
Othmar


^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2002-12-01 23:22 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-12-01 19:07 Getting rid of the masses of ip_conntrack messages hard__ware
2002-12-01 20:13 ` Othmar Pasteka
  -- strict thread matches above, loose matches on Subject: below --
2002-12-01 23:22 hard__ware
2002-12-01 21:46 hard__ware
2002-12-01 10:04 Othmar Pasteka
2002-12-01 20:33 ` Rob Sterenborg
2002-12-01 20:57   ` Othmar Pasteka
2002-12-01 22:03     ` Rob Sterenborg

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox