Re: Re: why do we need printk on sending syn flood cookie?

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Franchoze Eric
Date: Monday, August 2, 2010 - 2:14 pm

02.08.10, 22:10, "Mitchell Erblich" <erblichs@earthlink.net>:


There is no much settings to tune syn requests.
tcp_max_syn_backlog, tcp_synack_retries, tcp_abort_on_overflow
  
As for me, than I have about 3000 clients which do a little bit less then 3000 SYNs for nginx port.
I'm ok with sending syn cookies to clients. Also it's not possible to turn syncs off with setting
bigger value to tcp_max_syn_backlog and application works well so I would simple remove 
this messages from dmesg.

If I limit syncs with iptables it starts to drop needed packets. So it's no solution. That's why I think that we need turn off 
printk without turning off syn cookies.  

--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
why do we need printk on sending syn flood cookie?, Franchoze Eric, (Mon Aug 2, 12:58 am)
Re: why do we need printk on sending syn flood cookie?, Florian Westphal, (Mon Aug 2, 1:17 am)
Re: why do we need printk on sending syn flood cookie?, Mitchell Erblich, (Mon Aug 2, 11:10 am)
Re: Re: why do we need printk on sending syn flood cookie?, Franchoze Eric, (Mon Aug 2, 2:14 pm)
Re: why do we need printk on sending syn flood cookie?, Mitchell Erblich, (Mon Aug 2, 3:30 pm)
Re: why do we need printk on sending syn flood cookie?, Mitchell Erblich, (Mon Aug 2, 3:49 pm)