diff options
author | Ayuso/emailAddress=pablo@netfilter.org <Ayuso/emailAddress=pablo@netfilter.org> | 2007-12-21 18:15:04 +0000 |
---|---|---|
committer | Yasuyuki Kozakai <yasuyuki.kozakai@toshiba.co.jp> | 2007-12-23 03:14:44 +0900 |
commit | 735a6fc681809beb52c160b09507aa0999fbc6ba (patch) | |
tree | 2c51319a2940076f4a71c980766f8d68ee1ee431 /doc/stats/conntrackd.conf | |
parent | be072dced4efa3447a7c01d9f7dc90bd717fec7b (diff) | |
download | conntrack-tools-735a6fc681809beb52c160b09507aa0999fbc6ba.tar.gz conntrack-tools-735a6fc681809beb52c160b09507aa0999fbc6ba.zip |
rename `examples' directory to `doc'
Diffstat (limited to 'doc/stats/conntrackd.conf')
-rw-r--r-- | doc/stats/conntrackd.conf | 76 |
1 files changed, 76 insertions, 0 deletions
diff --git a/doc/stats/conntrackd.conf b/doc/stats/conntrackd.conf new file mode 100644 index 0000000..07deaa8 --- /dev/null +++ b/doc/stats/conntrackd.conf @@ -0,0 +1,76 @@ +# +# General settings +# +General { + # + # Number of buckets in the caches: hash table + # + HashSize 8192 + + # + # Maximum number of conntracks: + # it must be >= $ cat /proc/sys/net/ipv4/netfilter/ip_conntrack_max + # + HashLimit 65535 + + # + # Logfile: on, off, or a filename + # Default: on (/var/log/conntrackd.log) + # + #LogFile off + + # + # Syslog: on, off or a facility name (daemon (default) or local0..7) + # Default: off + # + #Syslog on + + # + # Lockfile + # + LockFile /var/lock/conntrack.lock + + # + # Unix socket configuration + # + UNIX { + Path /tmp/sync.sock + Backlog 20 + } + + # + # Netlink socket buffer size + # + SocketBufferSize 262142 + + # + # Increase the socket buffer up to maximun if required + # + SocketBufferSizeMaxGrown 655355 +} + +# +# Ignore traffic for a certain set of IP's: Usually +# all the IP assigned to the firewall since local +# traffic must be ignored, just forwarded connections +# are worth to replicate +# +IgnoreTrafficFor { + IPv4_address 127.0.0.1 # loopback +} + +# +# Do not replicate certain protocol traffic +# +IgnoreProtocol { + UDP +# ICMP +# IGMP +# VRRP + # numeric numbers also valid +} + +# +# Strip NAT traffic +# +StripNAT |