ip_conntrack: table full

Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware
Author Message
mcevoys
DD-WRT Novice


Joined: 03 Jul 2006
Posts: 3

PostPosted: Mon Jul 03, 2006 16:02    Post subject: ip_conntrack: table full Reply with quote
I switched from FreeMan to dd-wrt v23 this morning.

The router sends hundreds of these syslog messages to my console:

'ip_conntrack: table full, dropping packet.(kernel)'

Anyone have any ideas what this is, and how I can resolve it?
Sponsor
bigjohn
DD-WRT User


Joined: 08 Jun 2006
Posts: 123

PostPosted: Mon Jul 03, 2006 16:38    Post subject: Reply with quote
increase your connection limit? search for "bittorrent" on this forum... you'll find dozens of people who had to make adjustments to settings so that they could run their p2p stuff.
_________________
support DD-WRT and get great hosting!
mcevoys
DD-WRT Novice


Joined: 03 Jul 2006
Posts: 3

PostPosted: Mon Jul 03, 2006 16:50    Post subject: Reply with quote
Not running P2P, but I'll give it a shot.

Thanks!




Joined: 01 Jan 1970
Posts:

PostPosted: Mon Jul 03, 2006 18:54    Post subject: Reply with quote
You sure you don't have a virus or worm spreading proliferating from one of your systems?

This table is 512 members by default with DD-WRT and therefore fills up when there are 512 concurrent connections. Sometimes improperly closed TCP/IP connections can get stuck in here until the idle timeout is reached, but this shouldn't be happening to you.

It is very unlikely for a system doing 'normal' stuff and not P2P to have 512 concurrent connections. Very unlikely.
bigjohn
DD-WRT User


Joined: 08 Jun 2006
Posts: 123

PostPosted: Mon Jul 03, 2006 19:00    Post subject: Reply with quote
so true. I have 5 computers online now, and 3 Replay TV units, and an Xbox. Total connections = 240. And all devices are online and doing stuff. I have 30 tabs open in 3 instance of Firefox, for example...
_________________
support DD-WRT and get great hosting!
mcevoys
DD-WRT Novice


Joined: 03 Jul 2006
Posts: 3

PostPosted: Mon Jul 03, 2006 20:01    Post subject: Reply with quote
Nope, no viruses here.

But it is a larger home network, with 5 servers (including mail and 2 * www used by quite a few external users) and about 10 'inside the firewall' clients.

Also, the network management console itself probably adds quite a few connections across the router as it polls devices

My laptop alone has 60 firefox tabs open, so it's easy to see how I'd hit the 512 'wall'

Upping it to 4096 seems to have solved the large quantity of chatter at my network management console.
bigjohn
DD-WRT User


Joined: 08 Jun 2006
Posts: 123

PostPosted: Tue Jul 04, 2006 0:52    Post subject: Reply with quote
Shorten your timeouts too. Lower them to 500 at first, and if that does not eliminate the problem, lower them to something like 240.

That's the amount of time an inactive session can live. Anything under 200 and you run the risk of random connect/disconnect with AIM and MSN type clients.

John

_________________
support DD-WRT and get great hosting!
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum