2013/2/19 Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>: > There are several things that you can check to troubleshoot > conntrackd: > > 1) Log files: /var/log/conntrackd.log and /var/log/keepalived.log > 2) See if entries are actually synchronized via `conntrackd -i' and > `conntrackd -e' and other statistics. > 3) echo 255 > /proc/sys/net/netfilter/nf_conntrack_log_invalid, to > see if the connection tracking system is marking packets as invalid. > > I also suggest you to read the official documentation: > > http://conntrack-tools.netfilter.org/manual.html I had read the official documentation. I will keep testing to see if I can come up with more information. On a related note, am I understanding correctly that if external cache is disabled, then there's no need to use the notify_* scripts in keepalived.conf? or it's harmless to use them anyway? Thanks. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html