Re: Firewall problem

From: Glynn Clements (glynn@sensei.co.uk)
Date: Fri Jan 28 2000 - 05:17:07 EST


Fredrik Bergström wrote:

> Today I put up a firewall at work, and it works.
>
> But i have some problems, its very slow sometimes, and our ISP have a
> transparent cache machine running squid, and that should not be any
> problem, but very often it gives "Connection Lifetime Expired" error
> messages when surfing.
>
> Also the mails sent to the mail server will about 2 times of 3 not be
> sent.
>
> Is there any thing I can optimize on the linux firewall?

I wouldn't suggest changing random options until you've tried to
determine whether there is a specific cause (e.g. by tcpdump'ing the
connection).

> Also I cannot find any documentation about what to set, and not set in
> the /proc/sys/net/ipv4 dirs ?

/usr/src/linux/Documentation/networking/ip-sysctl.txt

documents the contents of /proc/sys/net/ipv4. It won't (and can't)
tell you what settings are right for you, though.

-- 
Glynn Clements <glynn@sensei.co.uk>

- To unsubscribe from this list: send the line "unsubscribe linux-net" in the body of a message to majordomo@vger.rutgers.edu



This archive was generated by hypermail 2b29 : Mon Jan 31 2000 - 21:00:33 EST