Linux Netfilter discussions
 help / color / mirror / Atom feed
* ip_conntrack growing indefinitely
@ 2007-08-07  3:02 Alexander Fortin
  0 siblings, 0 replies; 5+ messages in thread
From: Alexander Fortin @ 2007-08-07  3:02 UTC (permalink / raw)
  To: netfilter

Hi everybody. We're running a couple of Debian Sarge machines with 
2.4.31 kernel doing NAT for our network.
Recently we had troubles with lost packets because of full ip_conntrack 
buffers, and it's strange because usually the average number of 
connections is not more then 8000-10000.
For now it has been patched setting ip_conntrack_max to 65536 but 
connections still grow indefinitely (seems NAT never drops old connections).
Any idea of the reasons? Could be related with the kernel version (2 
years old) we're running?

Thanks

-- 
Alexander Fortin
IT Consultant
Informed Technology
E-mail: alieno@it.net.au
Ph: 08 9460 4888  Fax: 08 9460 4877


^ permalink raw reply	[flat|nested] 5+ messages in thread
[parent not found: <200708110801.l7B81Oj2025252@mail3.jubileegroup.co.uk>]
* libnetfilter_conntrack 0.0.81 release
@ 2007-07-28 12:38 Pablo Neira Ayuso
  2007-07-30 11:32 ` delete conntrack entry - how fd4
  0 siblings, 1 reply; 5+ messages in thread
From: Pablo Neira Ayuso @ 2007-07-28 12:38 UTC (permalink / raw)
  To: netfilter-announce, netfilter, Netfilter Development Mailinglist; +Cc: lwn

[-- Attachment #1: Type: text/plain, Size: 632 bytes --]

Hi!

The netfilter project proudly presents libnetfilter_conntrack-0.0.81

libnetfilter_conntrack is a userspace library providing a programming
interface (API) to the in-kernel connection tracking state table.

This release includes minor changes and bugfixes. See ChangeLog for more
details. Upgrade is recommended.

You can download it from:

http://www.netfilter.org/projects/libnetfilter_conntrack/
ftp://ftp.netfilter.org/pub/libnetfilter_conntrack/

Pablo (on behalf of the Netfilter Project)

-- 
"Será preciso viajar a través de los ojos de los idiotas" -- Poeta en
Nueva York -- Federico García Lorca.

[-- Attachment #2: ChangeLog --]
[-- Type: text/plain, Size: 345 bytes --]

libnetfilter_conntrack 0.0.81
======================================================================

Changes from 0.0.80:

- add layer 4 protocol comparison to nfct_compare()
	[Pablo Neira Ayuso]

- introduce nfct_nfnlh() to use functions like nfnl_rcvbufsiz()
	[Pablo Neira Ayuso]

- remove unused build_id() from build.c
	[Pablo Neira Ayuso]

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2007-08-12  6:23 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-08-07  3:02 ip_conntrack growing indefinitely Alexander Fortin
     [not found] <200708110801.l7B81Oj2025252@mail3.jubileegroup.co.uk>
2007-08-11 10:19 ` G.W. Haywood
2007-08-12  6:23   ` fd4
  -- strict thread matches above, loose matches on Subject: below --
2007-07-28 12:38 libnetfilter_conntrack 0.0.81 release Pablo Neira Ayuso
2007-07-30 11:32 ` delete conntrack entry - how fd4
2007-08-11  7:38   ` ip_conntrack growing indefinitely fd4
2007-08-11  8:04     ` Eric Leblond

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox