Re: Maxium concurrent connections with IPTables

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Monday 02 August 2004 8:01 pm, Antony Stone wrote:

> On Monday 02 August 2004 7:15 pm, Small, Jim wrote:
> > I'm curious, what is the maximum number of concurrent connections
> > possible with IPTables using connection tracking for udp and for tcp? 
> > (using latest 2.4 kernel and 2.6 kernel)
>
> Depends on the amount of memory in your machine, and the setting of
> /proc/sys/net/ipv4/ip_conntrack/max

Oops - that should be /proc/sys/net/ipv4/ip_conntrack_max of course.

Incidentally, if you don't change this value, it's calculated so that it uses 
approximately 5% of the system's memory (in other words, you should be able 
to increase the conntrack table capacity by a factor of about 20 on a system 
which isn't using memory for anything else).

Antony.

-- 
Software development can be quick, high quality, or low cost.

The customer gets to pick any two out of three.

                                                     Please reply to the list;
                                                           please don't CC me.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux