- Code: Select all
cat /proc/sys/net/ipv4/netfilter/ip_conntrack_count
or
- Code: Select all
wc -l /proc/net/ip_conntrack
- Code: Select all
cat /proc/sys/net/ipv4/netfilter/ip_conntrack_max
If you want to adjust it, just run the following as root:
- Code: Select all
echo 131072 > /proc/sys/net/ipv4/ip_conntrack_max
To make this persistent you have to add a line like 'net.ipv4.ip_conntrack_max=131072' to /etc/sysctl.conf.
http://rackerhacker.com/2008/01/24/ip_conntrack-table-full-dropping-packet/#comment-15408
Some readers may be interested to know what ip_conntrack is in the first place, and why it fills up. If ...