2005-04-14 21:47:10

by steve

[permalink] [raw]
Subject: 2.6.11.7 ip_conntrack: table full, dropping packet.


Hi,

I thought this problem has been fixed but apparently not in 2.6.11.7. Is
there any patch for it ? Thanks



Steve Kieu
PerfectPC Ltd. Technical Division.
Web: http://www.perfectpc.co.nz/
Ph: 04 461 7489
Mob: 021 137 0260


2005-04-14 22:25:33

by Daniel Andersen

[permalink] [raw]
Subject: Re: 2.6.11.7 ip_conntrack: table full, dropping packet.

[email protected] wrote:
>
> Hi,
>
> I thought this problem has been fixed but apparently not in 2.6.11.7. Is
> there any patch for it ? Thanks
>
>
>
> Steve Kieu
> PerfectPC Ltd. Technical Division.
> Web: http://www.perfectpc.co.nz/
> Ph: 04 461 7489
> Mob: 021 137 0260
> -
> To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
> the body of a message to [email protected]
> More majordomo info at http://vger.kernel.org/majordomo-info.html
> Please read the FAQ at http://www.tux.org/lkml/

Maybe you are thinking of a problem I'm not aware of, but have you tried
increasing /proc/sys/net/ipv4/ip_conntrack_max ?

Daniel Andersen

--

2005-04-14 22:32:18

by steve

[permalink] [raw]
Subject: Re: 2.6.11.7 ip_conntrack: table full, dropping packet.


Hi,

>
> Maybe you are thinking of a problem I'm not aware of, but have you tried
> increasing /proc/sys/net/ipv4/ip_conntrack_max ?

Ah, just check and discover, in 2.6.8 system the number is 8184 and in the
2.6.11.7 it is only 4088.

Will try to increase it now and see if the internet slugish disappear.
Thanks for the tip.

>
> Daniel Andersen
>
> --
>
> !DSPAM:425eed864196639116776!
>

2005-04-14 22:56:40

by Omkhar Arasaratnam

[permalink] [raw]
Subject: Re: 2.6.11.7 ip_conntrack: table full, dropping packet.

[email protected] wrote:

>
> Hi,
>
> I thought this problem has been fixed but apparently not in 2.6.11.7.
> Is there any patch for it ? Thanks
>
>
Are you sure the ip_conntrack itself isn't ACTUALLY full? Have you tried
increase this increasing this via
/proc/sys/net/ipv4/netfilter/ip_conntrack_max?

O




2005-04-14 23:01:01

by steve

[permalink] [raw]
Subject: Re: 2.6.11.7 ip_conntrack: table full, dropping packet.


> Are you sure the ip_conntrack itself isn't ACTUALLY full? Have you tried
> increase this increasing this via
> /proc/sys/net/ipv4/netfilter/ip_conntrack_max?

Just did it, thanks for reply. The 2.4 kernel I ran in the same box does
not have such problem, maybe there is a change in the algorithm of
calculating ip_contract_max in the recent kernel? What number you suggest
(my firewall box has only 64Mb of RAM)

Thanks,

Kind regards,