--- nexor@xxxxxxx wrote: > cat > /proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_established > > returns value: > 432000 > > Isn't that too much ? Too much or too less really depends upon your specific scenario. For this purpose you are provided with sysctls to alter the various timeouts. Specifically net.ipv4.netfilter.ip_conntrack_tcp_timeout_established ===== Regards, Kiran Kumar Immidi __________________________________ Do you Yahoo!? Yahoo! Small Business $15K Web Design Giveaway http://promotions.yahoo.com/design_giveaway/