Dismiss Notice

Welcome To SNBForums

SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.

If you'd like to post a question, simply register and have at it!

While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!

Conntrack table memory usage

Discussion in 'Asuswrt-Merlin' started by Denna, Apr 20, 2017 at 8:41 PM.

Tags:
  1. Denna

    Denna Regular Contributor

    Joined:
    Aug 4, 2016
    Messages:
    163
    @RMerlin,

    I've been looking at ways to minimize router resource usage caused by external Internet hosts.

    One of the ways to minimize CPU usage and conntrack table entries was to implement the following rule.

    Code:
    iptables -t mangle -I PREROUTING -i <wan_face> -m state --state NEW -j DROP
    On an Asus RT-AC88U, if you run the following command ...

    Code:
    sysctl net.ipv4.netfilter.ip_conntrack_max
    ... you get 300,000.

    Does that mean this router is configured with a maximum of 300,000 simultaneous connections ?

    If each conntrack entry is 350 bytes, doesn't that amount to more than 100 MB of memory usage ?

    Is that right ?​
     
    Last edited: Apr 20, 2017 at 8:46 PM

Share This Page