Can someone guide me on "kernel: nf_conntrack: table full, dropping packet"?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi all,

I am running linux bridge using iptables version 1.3.5 on FC5 with
kernel 2.6.20-1.2320.fc5smp

However, after running it for almost 3 months, I just discovered the
error below in my message log and all the traffic will drop and later
comes up again.

I will be glad for any pointer that can assists.

Goksie

Nov 11 15:01:38 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:02:38 india-tiger kernel: nf_conntrack: table full, dropping packet.
Nov 11 15:02:38 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:02:39 india-tiger kernel: nf_conntrack: table full, dropping packet.
Nov 11 15:04:35 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:06:57 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:09:49 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:10:54 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:12:55 india-tiger last message repeated 2 times
Nov 11 15:15:22 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:16:38 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:18:01 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:19:57 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:23:12 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:24:37 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:26:37 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:30:01 india-tiger last message repeated 2 times
Nov 11 15:31:33 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:32:35 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:33:49 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:37:04 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:42:58 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:44:00 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:45:01 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:46:58 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:48:04 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:49:40 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:54:36 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:56:00 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 15:59:18 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 16:02:51 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 16:05:32 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 16:06:34 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 16:08:42 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 16:19:06 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 16:20:56 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 16:31:47 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 16:31:58 india-tiger kernel: nf_conntrack: table full, dropping packet.
Nov 11 16:36:05 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
Nov 11 17:05:23 india-tiger kernel: possible SYN flooding on port
3128. Sending cookies.
-
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux