Re: conntrackd failover works partially, was Re: conntrack performance test results in INVALID packets

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Pablo,

Pablo Neira Ayuso wrote:
>>> Is the firewall sending RST packets to the peer/server to close
>>> connections? If so, I remember a similar report with a RHEL kernel:

I do not see any RST packets, neither on server nor on client side.

I have done more tests this morning. Unfortunately, things are complicated:

I repeated a basic failover test lots of times while making 1.000.000
connections. This test with 1000 parallel connections breaks every time.
500 is OK every time.

The kernel only has problems with 1000 connections, and then only from
time to time. In most of the cases (I guess ca. 80% of all tests), I do
not need to unload/load the kernel modules, but only clear the conntrack
table to get it back up running. The other times I have to reload the
kernel modules in order to make the system work again. I cannot see any
pattern there.

Best regards
Bernhard
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux