This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| advanced-ctnf [2024/10/06 21:18] – [Conntrack / Netfilter] -Condense hogwild | advanced-ctnf [2024/11/27 00:29] (current) – [Miscellaneous] hogwild | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== Conntrack / Netfilter ====== | ====== Conntrack / Netfilter ====== | ||
| - | Settings | + | Settings |
| ===== Connections ===== | ===== Connections ===== | ||
| - | The Connections | + | The Connections |
| - | In general, conntrack | + | Generally, conntrack |
| - | Clicking on the [// Count current ... //] link gives you a real-time view of the current demand for oconnections. | + | ("/proc/sys/net/ipv4/ |
| - | **Hash Table Size**: | + | Clicking the [// Count current ... //] link displays a real-time view of the current demand for connections. |
| + | |||
| + | \\ | ||
| + | |||
| + | **Hash Table Size**: | ||
| \\ | \\ | ||
| Line 21: | Line 25: | ||
| ===== TCP Timeout ===== | ===== TCP Timeout ===== | ||
| - | The TCP Timeout | + | This table lets you define some critical TCP parameters, such as timeouts. These affect only connections towards the router and not through the router. |
| \\ | \\ | ||
| Line 48: | Line 52: | ||
| ===== Tracking/ | ===== Tracking/ | ||
| - | Some protocols are well-known for being poorly designed to work with NAT. Some workarounds (Helpers) have been developed to allow these protocols to operate in a NAT environment. Enabling the option will enable the helper procedure. | + | Some protocols are well-known for being poorly designed to work with NAT. Some workarounds (Helpers) have been developed to allow these protocols to operate in a NAT environment. Enabling the option will enable the corresponding |
| - | Be advised that on networks where VoIP is in use, the use of the SIP helper is //not// recommended. While this may seem counterintuitive, | + | Be advised that on networks where VoIP is in use, the use of the SIP helper is //not// recommended. While it may seem counterintuitive, |
| \\ | \\ | ||
| Line 59: | Line 63: | ||
| ===== Miscellaneous ===== | ===== Miscellaneous ===== | ||
| - | **TCP/UDP Buffers**: | + | **TCP/UDP Buffers**: defines the number |
| - | **TTL Adjust**: | + | This needs to be tweaked carefully. A large buffer will facilitate higher throughput, but if too large, might create // |
| + | |||
| + | \\ | ||
| + | |||
| + | **TTL Adjust**: | ||
| + | |||
| + | \\ | ||
| - | **Inbound Layer 7**: This enables Layer 7 matching for inbound | + | **Inbound Layer 7**: enables |
| \\ | \\ | ||