Linux Netfilter discussions
 help / color / mirror / Atom feed
* Disabling conntrack for local net
@ 2009-10-23  3:00 Gary Smith
  2009-10-23  5:09 ` Mart Frauenlob
  0 siblings, 1 reply; 7+ messages in thread
From: Gary Smith @ 2009-10-23  3:00 UTC (permalink / raw)
  To: 'netfilter@vger.kernel.org'

We have several IP's NAT'd in from public interface.  Even with that we noticed that 80% or so of the connection entries appear to be local to local traffic.

We have the following subnets

10.40.16.0/24 (NAT'd public)
10.40.17.0/24 (internal data)
10.40.18.0/24 (internal data)
10.40.19.0/24 (internal data)
10.40.20.0/24 (NAT'd public)

Public internface NAT's mostly to 10.40.16.0/24 IP's, and a couple on the 10.40.20.0/24 IP's.  We have data/internal services on the 10.40.17.0/24 and 10.40.18.0/24.  We see lots of connections from the 10.40.16.0/24 to the data/internal getting entered into the conntrack (as you would normally expect).  

So, is there any benefit of not conntracking these?  Is so, how do I do that without breaking the NAT.

I know I did this years ago, I just can't remember how.

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2009-11-17 16:35 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-10-23  3:00 Disabling conntrack for local net Gary Smith
2009-10-23  5:09 ` Mart Frauenlob
2009-10-23  6:22   ` Mart Frauenlob
2009-10-23 16:26     ` Gary Smith
2009-11-16 23:32       ` Gary Smith
2009-11-17 10:03         ` Mart Frauenlob
2009-11-17 16:35           ` Gary Smith

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox