Re: ip_conntrack_max

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thursday 08 July 2004 2:13 pm, Fallucchi Antonio wrote:

> Antony Stone wrote:
>
> oh!, excuse me for the html!

Thanks for turning it off.

> I have 20 computer in the lan and 5 server.

In that case a 128Mbyte machine should have no trouble.

> Another questions: how I can limit the number of connection for every
> computer?

This is difficult.   I think we should start by asking "what do you mean by a 
connection?"   Remember that many web browsers, for example, will open 5-10 
simultaneous connections in order to load all the elements of a web page.   
DNS needs its own connections in order to do name lookups.   Some connections 
are long-term (eg: telnet, ssh - even when you're not typing, the connection 
is still there), some are very transient (eg: http - once you have the page 
displayed, there's no connection between your browser and the server until 
you click on another hyperlink).

Why do you want to limit connections per machine?   What are you trying to 
achieve?

> >What is the value in /proc/sys/net/ipv4/ip_conntrack_max ?
>
> ip_conntrack_max now is 10240.

That sounds fine.   Tell us if you get "connection tracking table full" errors 
again.

Regards,

Antony.

-- 
Success is a lousy teacher.  It seduces smart people into thinking they can't 
lose.

 - William H Gates III

                                                     Please reply to the list;
                                                           please don't CC me.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux