Re: "Operation not permitted" from nf_conntrack under high UDP load

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Kevin,

On Fri, Mar 4, 2016 at 4:59 AM, Kevin Holly <root@xxxxxxxxxx> wrote:
> you might want to check your system logs for messages similar to "ip_conntrack: table full, dropping packet." because for me this sounds like a problem with the size of the connection tracking table not being large enough for the number of connections you're dealing there.

As I wrote, we have a max for the connection tracking table of 800k
set, and it is filled with about 300k entries, so this is definitely
not the problem. We also don't see those log messages you mentioned. I
was aware of those, and I've seen them before on other systems, but on
this machine, this is definitely not the problem.

Any other hints, anyone?

Best Regards,
Sebastian
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux