[prev in list] [next in list] [prev in thread] [next in thread] 

List:       netfilter
Subject:    Re: Max. limit reached -> box unusable
From:       David Ford <david () kalifornia ! com>
Date:       2000-07-29 2:32:29
[Download RAW message or body]

Well Rusty... :)

I, being the only one with GRE tunneling, and with sound mind and body...

...it doesn't work.  Once it fills up, printks flood the console and 
logs and new connections fail completely.  ICMP doesn't even work.

test5 is out, does it have this patch in it?  I'll try it again as soon 
as I get a spare millisecond.

-d

Rusty Russell wrote:
> 
> In message <20000725130923.5277.qmail@oknodo.bof.de> you write:
> > > If the kernel's table is too full to add to the conn track table,
> > > it should go "oh well" and continue on instead of completely
> > > breaking the network.
> 
> It does, modulo any bugs.  The overload code (with the syn flood
> patch) seems to work quite well.
> 
> Rusty.
> --
> Hacking time.
> 



[Attachment #3 (text/html)]

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
<html><head></head><body>Well Rusty... :)<br>
<br>
I, being the only one with GRE tunneling, and with sound mind and body...<br>
<br>
...it doesn't work.&nbsp; Once it fills up, printks flood the console and logs
 and new connections fail completely.&nbsp; ICMP doesn't even work.<br>
<br>
test5 is out, does it have this patch in it?&nbsp; I'll try it again as soon as I get \
a spare millisecond.<br> <br>
-d<br>
<br>
Rusty Russell wrote:<br>
<blockquote type="cite" cite="mid:20000726234011.7D25881C6@halfway">
<div class="text-plain"><pre wrap>In message <a class="txt-link txt-link-rfc2396E" \
href="mailto:20000725130923.5277.qmail@oknodo.bof.de">&lt;20000725130923.5277.qmail@oknodo.bof.de&gt;</a> \
you write: &gt; &gt; If the kernel's table is too full to add to the conn track \
table, &gt; &gt; it should go "oh well" and continue on instead of completely
&gt; &gt; breaking the network.

It does, modulo any bugs.  The overload code (with the syn flood
patch) seems to work quite well.

Rusty.
--
Hacking time.
</pre></div>
</blockquote>
<br>
<br>
</body>
</html>



[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic