Gentoo Archives: gentoo-user

From: Andrey Falko <ma3oxuct@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Gentoo router: Conntrack table full
Date: Sun, 23 Mar 2008 03:22:58
Message-Id: 350fc7cf0803222022m4dfb3827o878e39dd3493d20d@mail.gmail.com
In Reply to: [gentoo-user] Gentoo router: Conntrack table full by Dan Cowsill
1 On Sat, Mar 22, 2008 at 11:16 PM, Dan Cowsill <danthehat@×××××.com> wrote:
2 > Hi folks,
3 >
4 > Today I had some really serious problems with my Gentoo router. I
5 > could ping it, and all the network connections were in place and
6 > functional, but no outside access. I looked into it and found that
7 > the syslog was flooded with this:
8 >
9 >
10 > Mar 22 21:25:55 localhost kernel: nf_conntrack: table full, dropping packet.
11 > Mar 22 21:26:00 localhost kernel: printk: 11 messages suppressed.
12 > Mar 22 21:26:00 localhost kernel: nf_conntrack: table full, dropping packet.
13 > Mar 22 21:26:05 localhost kernel: printk: 16 messages suppressed.
14 >
15 >
16 > These messages spanned a full 20 hours of the log. I understand that
17 > conntrack is the connection tracking system that iptables uses. I
18 > also understand that its maximum is something on the order of 65000
19 > simultaneous connections. For a simple home network, I think we can
20 > agree that I would probably never approach this number of connections
21 > with normal use.
22 >
23 > So my question is this: what could have caused the router's
24 > connection tracker to overflow?
25 > --
26 > Dan Cowsill
27 > http://www.danthehat.net
28 > --
29 > gentoo-user@l.g.o mailing list
30 >
31 >
32
33 What type of 'net services do you run between your home network and
34 the outside? Is there a possibility that someone out have put a denial
35 of service attack on you?
36 --
37 gentoo-user@l.g.o mailing list

Replies

Subject Author
Re: [gentoo-user] Gentoo router: Conntrack table full Dan Cowsill <danthehat@×××××.com>