diff options
author | Florian Westphal <fw@strlen.de> | 2021-08-26 15:54:19 +0200 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2021-08-30 11:49:54 +0200 |
commit | d532bcd0b2699d84d71a0c71d37157ac6eb3be25 (patch) | |
tree | af1c997d9ea725f60249456b7b04f0c4500d4305 /net/netfilter/nft_redir.c | |
parent | e3245a7b7b34bd2e97f744fd79463add6e9d41f4 (diff) | |
download | linux-d532bcd0b2699d84d71a0c71d37157ac6eb3be25.tar.gz linux-d532bcd0b2699d84d71a0c71d37157ac6eb3be25.tar.bz2 linux-d532bcd0b2699d84d71a0c71d37157ac6eb3be25.zip |
netfilter: conntrack: sanitize table size default settings
conntrack has two distinct table size settings:
nf_conntrack_max and nf_conntrack_buckets.
The former limits how many conntrack objects are allowed to exist
in each namespace.
The second sets the size of the hashtable.
As all entries are inserted twice (once for original direction, once for
reply), there should be at least twice as many buckets in the table than
the maximum number of conntrack objects that can exist at the same time.
Change the default multiplier to 1 and increase the chosen bucket sizes.
This results in the same nf_conntrack_max settings as before but reduces
the average bucket list length.
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'net/netfilter/nft_redir.c')
0 files changed, 0 insertions, 0 deletions