Gentoo Archives: gentoo-user

From: Dan Cowsill <danthehat@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Gentoo router: Conntrack table full
Date: Sun, 23 Mar 2008 03:26:20
Message-Id: 4ef07b8c0803222026y2aacbddfwdc1985467f134c80@mail.gmail.com
In Reply to: Re: [gentoo-user] Gentoo router: Conntrack table full by Andrey Falko
1 On Sat, Mar 22, 2008 at 11:22 PM, Andrey Falko <ma3oxuct@×××××.com> wrote:
2 >
3 > On Sat, Mar 22, 2008 at 11:16 PM, Dan Cowsill <danthehat@×××××.com> wrote:
4 > > Hi folks,
5 > >
6 > > Today I had some really serious problems with my Gentoo router. I
7 > > could ping it, and all the network connections were in place and
8 > > functional, but no outside access. I looked into it and found that
9 > > the syslog was flooded with this:
10 > >
11 > >
12 > > Mar 22 21:25:55 localhost kernel: nf_conntrack: table full, dropping packet.
13 > > Mar 22 21:26:00 localhost kernel: printk: 11 messages suppressed.
14 > > Mar 22 21:26:00 localhost kernel: nf_conntrack: table full, dropping packet.
15 > > Mar 22 21:26:05 localhost kernel: printk: 16 messages suppressed.
16 > >
17 > >
18 > > These messages spanned a full 20 hours of the log. I understand that
19 > > conntrack is the connection tracking system that iptables uses. I
20 > > also understand that its maximum is something on the order of 65000
21 > > simultaneous connections. For a simple home network, I think we can
22 > > agree that I would probably never approach this number of connections
23 > > with normal use.
24 > >
25 > > So my question is this: what could have caused the router's
26 > > connection tracker to overflow?
27 > > --
28 > > Dan Cowsill
29 > > http://www.danthehat.net
30 > > --
31 > > gentoo-user@l.g.o mailing list
32 > >
33 > >
34 >
35 > What type of 'net services do you run between your home network and
36 > the outside? Is there a possibility that someone out have put a denial
37 > of service attack on you?
38 > --
39 > gentoo-user@l.g.o mailing list
40 >
41 >
42
43 I have SSH to a server, two open ports for bit torrent connections and
44 a few ranges for DCC transfers from irc.
45
46 The possibility of a DoS attack is pretty real, I imagine. Is there
47 any way I could be sure?
48
49 --
50 Dan Cowsill
51 http://www.danthehat.net
52 --
53 gentoo-user@l.g.o mailing list

Replies

Subject Author
Re: [gentoo-user] Gentoo router: Conntrack table full Michal 'vorner' Vaner <vorner@×××.cz>