@RMerlin,
I've been looking at ways to minimize router resource usage caused by external Internet hosts.
One of the ways to minimize CPU usage and conntrack table entries was to implement the following rule.
On an Asus RT-AC88U, if you run the following command ...
... you get 300,000.
Does that mean this router is configured with a maximum of 300,000 simultaneous connections ?
If each conntrack entry is 350 bytes, doesn't that amount to more than 100 MB of memory usage ?
Is that right ?
One of the ways to minimize CPU usage and conntrack table entries was to implement the following rule.
Code:
iptables -t mangle -I PREROUTING -i <wan_face> -m state --state NEW -j DROP
On an Asus RT-AC88U, if you run the following command ...
Code:
sysctl net.ipv4.netfilter.ip_conntrack_max
Does that mean this router is configured with a maximum of 300,000 simultaneous connections ?
If each conntrack entry is 350 bytes, doesn't that amount to more than 100 MB of memory usage ?
Is that right ?
Last edited: