Shawn Perkins <[EMAIL PROTECTED]> wrote:
>
> ipchains -M -S 480 480 0

The first number is the timeout for active TCP connections.  The second
is for TCP connections which have been closed.  The third is for UDP
"connections".

You really shouldn't use a value of 0 for UDP, because it makes DNS
replies from the internet impossible.  If you don't pass UDP to the
internet at all, though, no big deal, I guess.

The second number, TCP connections that are closed, should never need to
be higher than 120.  That is the RFC-imposed limit for cleaning up
closed TCP connections.  You could make it less, if you have a lot of
TCP connections being opened and closed, but I'd keep it between 30 and
120.  Certainly not as high as 480.

Your first number, for active connections, is only 4 minutes!  A
connection that sends no data for four minutes will be "forgotten" and
dropped!  You should at least make it a couple of hours, as others have
suggested.

-- 
   [EMAIL PROTECTED] (Fuzzy Fox)      || "Nothing takes the taste out of peanut
sometimes known as David DeSimone  ||  butter quite like unrequited love."
  http://www.dallas.net/~fox/      ||                       -- Charlie Brown


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to