WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

RE: [Xen-users] ip conntrack table full

To: "Mike McGrath" <mmcgrath@xxxxxxxxxx>, <xen-users@xxxxxxxxxxxxxxxxxxx>
Subject: RE: [Xen-users] ip conntrack table full
From: "James Harper" <james.harper@xxxxxxxxxxxxxxxx>
Date: Mon, 25 Jan 2010 10:44:23 +1100
Cc:
Delivery-date: Sun, 24 Jan 2010 15:45:02 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <alpine.LFD.2.00.1001241728170.16075@xxxxxxxxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <alpine.LFD.2.00.1001241728170.16075@xxxxxxxxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
Thread-index: AcqdTc51R0+2mGxbQh2Od+Li4RE4JQAAThhQ
Thread-topic: [Xen-users] ip conntrack table full
> 
> xen-3.0.3-94.el5_4.2
> 2.6.18-164.6.1.el5xen
> RHEL5.4 x86_64
> 
> I've got a dom0 that does nothing but have a DomU created.  The DomU
gets
> plenty of load.  Over time, the dom0's ipconntrack table fills up but
not
> the DomU.  Once it gets full I can restart iptables and it's fine.
> 
> The strange thing is this only happens on hosts I have provided
(hardware
> and hosting) from one location.  I'm not really sure what kind of
boxes
> they are or if the architecture is a red herring.
> 
> I sure would like to know what is going on, the network setup is
bridged
> but the dom0 is the domU's gateway host (don't ask why I'm doing both)
> 
> Any thoughts?
> 

'cat /proc/net/ip_conntrack' will tell you what's in the conntrack
database. Have a look in there and see if it's what you expect...

James

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users