From: "Daniel P. Berrange" <berrange@redhat.com>
To: David Ahern <dsahern@gmail.com>
Cc: "Richard W.M. Jones" <rjones@redhat.com>, qemu-devel@nongnu.org
Subject: Re: [Qemu-devel] PATCH: enabling TCP keepalives - v3
Date: Fri, 1 May 2009 16:23:12 +0100 [thread overview]
Message-ID: <20090501152312.GH13308@redhat.com> (raw)
In-Reply-To: <49FAEFDD.2070002@gmail.com>
On Fri, May 01, 2009 at 06:49:33AM -0600, David Ahern wrote:
>
>
> Richard W.M. Jones wrote:
> > On Thu, Apr 30, 2009 at 01:40:42PM -0600, David Ahern wrote:
> >> Did not see a response to the last version.
> >>
> >> This patch enables TCP keepalives on VNC connections and TCP-based char
> >> devices.
> >>
> >> Default parameters have keep alive probes sent after 60-seconds of idle
> >> time. Probes are sent every 12 seconds with the connection resetting
> >> after 5 failed probes (ie., connection is closed if no response received
> >> in 60-seconds).
> >
> > IMHO this should be optional, and firmly default to _OFF_. Brief
> > network outages shouldn't result in connections failing all over the
> > place. In addition, does this negatively impact migration?
>
> It's not a matter of connections failing; it's a matter of cleaning them
> up for a variety of reasons. Besides the VPN example which motivated
> this patch (i.e, VPN connection drops and when re-established you get a
> differnt IP), there are a lot of networks with very aggressive firewalls
> (e.g., 60-minute timers). Without some sort of keepalive mechanisms
> those firewalls will close the holes and the connections will hang.
You don't neccessarily always get a different IP for VPN connections,
as administrators may well choose to give users a fixed IP for their
VPN client. I'm not entirely against keepalives, but I thing making
it drop the connection after a mere 60 seconds is way too quick, if this
is enabled by default. I'd be more inclined to just have it use the
kernel defaults for timeouts
Daniel
--
|: Red Hat, Engineering, London -o- http://people.redhat.com/berrange/ :|
|: http://libvirt.org -o- http://virt-manager.org -o- http://ovirt.org :|
|: http://autobuild.org -o- http://search.cpan.org/~danberr/ :|
|: GnuPG: 7D3B9505 -o- F3C9 553F A1DA 4AC2 5648 23C1 B3DF F742 7D3B 9505 :|
next prev parent reply other threads:[~2009-05-01 15:23 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-04-30 19:40 [Qemu-devel] PATCH: enabling TCP keepalives - v3 David Ahern
2009-05-01 11:32 ` Richard W.M. Jones
2009-05-01 12:23 ` Jamie Lokier
2009-05-01 12:49 ` David Ahern
2009-05-01 15:23 ` Daniel P. Berrange [this message]
2009-05-01 15:47 ` David Ahern
2009-05-01 17:21 ` Richard W.M. Jones
2009-05-05 1:31 ` Jamie Lokier
2009-05-05 2:59 ` David Ahern
2009-05-01 15:52 ` Avi Kivity
2009-05-01 16:11 ` John Haxby
2009-05-05 1:35 ` Jamie Lokier
2009-05-01 14:43 ` Anthony Liguori
2009-05-01 14:47 ` David Ahern
2009-05-01 14:51 ` Anthony Liguori
2009-05-01 15:16 ` Paul Brook
2009-05-01 15:57 ` Anthony Liguori
2009-05-01 16:04 ` Paul Brook
2009-05-01 16:11 ` David Ahern
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20090501152312.GH13308@redhat.com \
--to=berrange@redhat.com \
--cc=dsahern@gmail.com \
--cc=qemu-devel@nongnu.org \
--cc=rjones@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).