IPTables state table timeout

IPTables state table timeout

Post by <ba.. » Wed, 08 May 2002 11:40:02



I am having some problems with a VPN client behind an IPTables masqing firewall that I have managed to trace down to a timeout value that the state table uses.  The default values are 30 seconds (30hz) for a connection, 180 seconds (180hz) for a stream.  Does anyone know of a way to change this value at runtime or must I edit the source? Thanks

                 Jason
         www.cyborgworkshop.com
...and the geek shall inherit the earth...

 
 
 

IPTables state table timeout

Post by jeff » Wed, 08 May 2002 14:53:39


On the glorious day of Mon, 6 May 2002 21:40:02 -0500,

Quote:>I am having some problems with a VPN client behind an IPTables masqing firewall that I have managed to trace down to a timeout value that the state table uses.  

The default values are 30 seconds (30hz) for a connection, 180 seconds
(180hz) for a stream.  Does anyone know of a way to change this value
at runtime or must I edit the source? Thanks

Quote:

>                 Jason
>         www.cyborgworkshop.com
>...and the geek shall inherit the earth...

Well, i dont think you can change that on the fly.
I could be verry wrong here, but I think you might have to edit one or
more ip_conntrack_*.c files in the kernel source and rebuild that
module..

 
 
 

1. iptables v1.2.2: can't initialize iptables table `filter': Table does not exist

I have the following error when I try to use iptables...
Any idea? Thanks.


Linux gw2 2.4.10 #1 Sun Sep 30 00:09:25 EEST 2001 i586 unknown

Module                  Size  Used by
ip_conntrack           12784   0  (unused)
ip_tables              10752   0  (unused)
8139too                11040   1
dmfe                   12640   1

iptables v1.2.2: can't initialize iptables table `filter': Table does not
exist
(do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.

2. COLA FAQ 3 of 7 13-Sep-2002

3. /var/lock permissions and kermit?

4. what does "-m state --state NEW,ESTABLISHED" mean when used in iptables config file?

5. Problems with X under redhat 6.1

6. iptable timeout ?? (question on timeout features of ipchains)

7. HELP: lprm not working

8. CONFIG: timeout - Timeout table free list empty (min_free_callouts = 50 exceeded)

9. iptables "can't initialize iptables table `filter'"

10. Tuning timeout in tcp protocol state

11. iptables & state module

12. Sizing the State Tables