On 11/6/06, Guy Boisvert <boisvert dot guy at videotron dot ca> wrote:
>
> I'd lower UDP/TCP timeout value. In P2P, there is often a lot of
> leftout connections, decreasing the UDP/TCP timeout helps to keep the
> number of connections lower thus keeping state table from filling. In
> mOnOwall, default TCP Timeout is 2.5 hours from 1.2b2.
>
That's a good idea. It may or may not help though. Some of those P2P
apps, with settings that allow them to get out of control, could have
30,000 active sessions open. It could also be that it's a buggy app
and leaves open connections hanging, in which case decreasing the time
out should help (by how much is hard to say).
-Chris |