Re: Strange Contracker problem in conjuction with Cisco Content Switch

2002-03-29 Thread Patrick Schaaf
Two questions regardin this strange effect: a) Is there a performance penalty for this huge number of connections in contracker? Yes. This has been discussed, with possible remedies (hashsize parameter to ip_conntrack) mentioned, about a week ago. See the thread at

Re: Strange Contracker problem in conjuction with Cisco Content Switch

2002-03-29 Thread Harald Welte
On Fri, Mar 29, 2002 at 09:07:54AM +0100, Martin Sperl wrote: Hi! Two questions regardin this strange effect: a) Is there a performance penalty for this huge number of connections in contracker? not if you widen the hash table (see list archive on discussions about that). b) Why does it

Re: Strange Contracker problem in conjuction with Cisco Content Switch

2002-03-29 Thread Patrick Schaaf
On Fri, Mar 29, 2002 at 09:59:58AM +0100, Harald Welte wrote: b) Why does it occure primarily with the Cisco Content Switch. The numbers were much lower before utilising the content switch! So the CSS is ACK flooding! Is there a strange interaction between the CSS and

Strange Contracker problem in conjuction with Cisco Content Switch

2002-03-28 Thread Martin Sperl
Hi! We are experiencing problems with connection tracking with a Cisco Content Switch behind a firewall and think that it might partly be a problem with netfilter in stock Linux 2.4.17. We just started using CSS in a productive environment and now the number of connections in