On Dec 27, 2005 at 1722 +0100, DEXTER appeared and said: > [...] > So my question is: How to handle this situation? I mean, just 1 NAT > linux box is able to handle all the 400+ users with the above > situations? Or we have to do something like CONNLIMIT on source ips? Is > there possibilities to balance the traffic on 2 or more NAT box? Just a wild guess, I would try to look at the timeouts in /proc/sys/net/ipv4/netfilter/ and see if you can reduce some of them. In addition to that I would increase the IP pool for NAT on the outgoing interface(s). You don't need two boxes for that, just multiple IP addresses on the interface. Best wishes, René. -- )\._.,--....,'``. Let GNU/Linux work for you while you take a nap. /, _.. \ _\ (`._ ,. R. Pfeiffer <lynx at luchs.at> + http://web.luchs.at/ `._.-(,_..'--(,_..'`-.;.' - System administration + Consulting + Teaching -
Attachment:
pgpOSoOH6jFUE.pgp
Description: PGP signature