Re: ip_conntrack_tcp Errors

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Monday 28 June 2004 12:47 pm, Evgeni Vachkov wrote:

> Hi all,
>
> When I load test one of our firewalls, when the concurrent connections
> reach arround 230, I am getting a lot of error messages as shown below.

230 is a very small number.   You should be able to support several thousand 
connections (depending on RAM) without problems.

> Mostly indicating that the server has sent an invalid SYN.  This is a
> heavy load firewall.

Define "heavy load"?

230 connections is not much.   What sort of bandwidth are they generating in 
total?

What sort of network cards are you using?   Anything changed about the 
hardware around the time you started seeing the messages?

Regards,

Antony.

-- 
What is this talk of "software release"?
Our software evolves and matures until it is capable of escape, leaving a 
bloody trail of designers and quality assurance people in its wake.

                                                     Please reply to the list;
                                                           please don't CC me.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux