starchy,
@starchy@infosec.exchange avatar

@jerry Just getting back to this now. Mind you this was on a less recent Debian version, so ymmv, but I had the line

net.netfilter.nf_conntrack_max = 4000000

in /etc/sysctl.d/netfilter.conf. You can also echo the value to /proc/net/netfilter/nf_conntrack_max if you want to set it without a reboot.

If the values of /proc/net/netfilter/nf_conntrack_count and /proc/net/netfilter/nf_conntrack_max are ever equal, you're in trouble for sure.

Also note this will be under /proc/net/ipv4 or /proc/net/ipv6 on some distros.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • KamenRider
  • Ask_kbincafe
  • TheResearchGuardian
  • KbinCafe
  • Socialism
  • oklahoma
  • SuperSentai
  • feritale
  • All magazines