This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
advanced-ctnf [2023/05/08 00:44] – [Connections] -expanded explain conntrack system hogwild | advanced-ctnf [2024/11/27 00:29] (current) – [Miscellaneous] hogwild | ||
---|---|---|---|
Line 1: | Line 1: | ||
====== Conntrack / Netfilter ====== | ====== Conntrack / Netfilter ====== | ||
- | The settings in this menu allow you to control some advanced network parameters. In most cases, | + | Settings here let you control some advanced network parameters. In most cases, default settings are fine. Think carefully before changing the settings from defaults. You should only change these settings if you have advanced networking knowledge. |
===== Connections ===== | ===== Connections ===== | ||
- | The Connections | + | The Connections |
- | In general, conntrack | + | Generally, conntrack |
- | Clicking on the [// Count current ... //] link gives you a real-time view of the current demand for oconnections. | + | ("/proc/sys/net/ipv4/ |
- | **Hash Table Size**: | + | Clicking the [// Count current ... //] link displays a real-time view of the current demand for connections. |
+ | |||
+ | \\ | ||
+ | |||
+ | **Hash Table Size**: | ||
\\ | \\ | ||
Line 21: | Line 25: | ||
===== TCP Timeout ===== | ===== TCP Timeout ===== | ||
- | The TCP Timeout | + | This table lets you define some critical TCP parameters, such as timeouts. These affect only connections towards the router and not through the router. |
\\ | \\ | ||
Line 48: | Line 52: | ||
===== Tracking/ | ===== Tracking/ | ||
- | Some protocols are well-known for being poorly designed to work with NAT. Some workarounds (Helpers) have been developed to allow these protocols to operate in a NAT environment. Enabling the option will enable the helper procedure. | + | Some protocols are well-known for being poorly designed to work with NAT. Some workarounds (Helpers) have been developed to allow these protocols to operate in a NAT environment. Enabling the option will enable the corresponding |
- | Be advised that on networks where VoIP is in use, the use of the SIP helper is //not// recommended. While this may seem counterintuitive, | + | Be advised that on networks where VoIP is in use, the use of the SIP helper is //not// recommended. While it may seem counterintuitive, |
\\ | \\ | ||
Line 59: | Line 63: | ||
===== Miscellaneous ===== | ===== Miscellaneous ===== | ||
- | **TCP/UDP Buffers**: | + | **TCP/UDP Buffers**: defines the number |
- | **TTL Adjust**: | + | This needs to be tweaked carefully. A large buffer will facilitate higher throughput, but if too large, might create // |
- | **Inbound Layer 7**: This enables Layer 7 matching for inbound | + | \\ |
+ | |||
+ | **TTL Adjust**: lets you increase or decrease the packet Time-To-Live value crossing the router. | ||
+ | |||
+ | \\ | ||
+ | |||
+ | **Inbound Layer 7**: enables | ||
\\ | \\ | ||
{{: | {{: | ||
+ | |||
+ | \\ | ||
+ | |||
+ | \\ \\ | ||