kernel: ip_conntrack: table full, dropping packet



zaplneni ip_conntrack tabulky - nejcasteji P2P programy...

zjistit velikost:
cat /proc/sys/net/ipv4/ip_conntrack_max

pripadne zvetsit:
echo 65535 > /proc/sys/net/ipv4/ip_conntrack_max

vypsat zaznamy / spocitat radky (zaznamy):
cat /proc/net/ip_conntrack | wc -l


novejsi kernely (2.6?) jiz maji vse luxusne v:
/proc/sys/net/ipv4/netfilter

takze napr. pocet zaznamu:
cat /proc/sys/net/ipv4/netfilter/ip_conntrack_count

10x zkratit zivotnost zaznamu tcp established (default 432000 = 5 dnu):
echo 43200 > /proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_established
Last update:
2007-10-10 13:47
Author:
Daniel
Revision:
1.39
Average rating:0 (0 Votes)

You cannot comment on this entry

Chuck Norris has counted to infinity. Twice.