Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: ip_conntrack_max
Date: Thu, 8 Jul 2004 14:29:24 +0100	[thread overview]
Message-ID: <200407081429.24492.Antony@Soft-Solutions.co.uk> (raw)
In-Reply-To: <40ED4865.7020208@cisbic.com>

On Thursday 08 July 2004 2:13 pm, Fallucchi Antonio wrote:

> Antony Stone wrote:
>
> oh!, excuse me for the html!

Thanks for turning it off.

> I have 20 computer in the lan and 5 server.

In that case a 128Mbyte machine should have no trouble.

> Another questions: how I can limit the number of connection for every
> computer?

This is difficult.   I think we should start by asking "what do you mean by a 
connection?"   Remember that many web browsers, for example, will open 5-10 
simultaneous connections in order to load all the elements of a web page.   
DNS needs its own connections in order to do name lookups.   Some connections 
are long-term (eg: telnet, ssh - even when you're not typing, the connection 
is still there), some are very transient (eg: http - once you have the page 
displayed, there's no connection between your browser and the server until 
you click on another hyperlink).

Why do you want to limit connections per machine?   What are you trying to 
achieve?

> >What is the value in /proc/sys/net/ipv4/ip_conntrack_max ?
>
> ip_conntrack_max now is 10240.

That sounds fine.   Tell us if you get "connection tracking table full" errors 
again.

Regards,

Antony.

-- 
Success is a lousy teacher.  It seduces smart people into thinking they can't 
lose.

 - William H Gates III

                                                     Please reply to the list;
                                                           please don't CC me.



  reply	other threads:[~2004-07-08 13:29 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-07-08  9:38 ip_conntrack_max Fallucchi Antonio
2004-07-08  9:56 ` ip_conntrack_max Antony Stone
2004-07-08 10:31   ` ip_conntrack_max Fallucchi Antonio
2004-07-08 10:52     ` ip_conntrack_max Antony Stone
2004-07-08 13:13       ` ip_conntrack_max Fallucchi Antonio
2004-07-08 13:29         ` Antony Stone [this message]
2004-07-08 17:02           ` ip_conntrack_max Fallucchi Antonio
2004-07-08 17:21           ` ip_conntrack_max Fallucchi Antonio
2004-07-08 17:42             ` ip_conntrack_max Antony Stone
2004-07-08 15:28         ` ip_conntrack_max James Sneeringer
2004-07-08  9:56 ` ip_conntrack_max Evgeni Vachkov
  -- strict thread matches above, loose matches on Subject: below --
2004-07-08  9:34 ip_conntrack_max Fallucchi Antonio
2003-02-13 19:04 ip_conntrack_max homsher

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200407081429.24492.Antony@Soft-Solutions.co.uk \
    --to=antony@soft-solutions.co.uk \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox