/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */



Audie Pierre <[EMAIL PROTECTED]> wrote:
>
> Strictly business is being conducted behind the firewall.  Actually,
> mostly DNS requests are using the UDP ports.

How high are your UDP timeouts set?  If you set them really high, like
15 minutes, then a large amount of DNS requests will end up filling up
your port lists.

With such high DNS traffic, you really should set up a caching-only
nameserver *on* the masq gateway.  This will prevent any need to
masquerade DNS traffic, and will further speed up processing of
redundant requests.  A win-win situation.

> The changes that I've made last Friday involve an upgrade from Redhat
> 5.2 / Kernel 2.0.36 to Redhat 6.0 / Kernel 2.3.9.  Hopefully, that
> will make a difference.

It won't.

> I also switched from ipfwadm to ipchains. 

Nor will that.

-- 
   [EMAIL PROTECTED] (Fuzzy Fox)      || "Nothing takes the taste out of peanut
sometimes known as David DeSimone  ||  butter quite like unrequited love."
  http://www.dallas.net/~fox/      ||                       -- Charlie Brown


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/

Reply via email to