# # Synchronizer settings # Sync { Mode NACK { # # Size of the buffer that hold destroy messages for # possible resends (in bytes) # ResendBufferSize 262144 # # Entries committed to the connection tracking table # starts with a limited timeout of N seconds until the # takeover process is completed. # CommitTimeout 180 # Set Acknowledgement window size ACKWindowSize 20 } # # Multicast IP and interface where messages are # broadcasted (dedicated link). IMPORTANT: Make sure # that iptables accepts traffic for destination # 225.0.0.50, eg: # # iptables -I INPUT -d 225.0.0.50 -j ACCEPT # iptables -I OUTPUT -d 225.0.0.50 -j ACCEPT # Multicast { IPv4_address 225.0.0.50 IPv4_interface 192.168.100.100 # IP of dedicated link Interface eth2 Group 3780 } # Enable/Disable message checksumming Checksum on # Uncomment this if you want to replicate just certain TCP states. # This option introduces a tradeoff in the replication: it reduces # CPU consumption and lost messages rate at the cost of having # backup replicas that don't contain the current state that the active # replica holds. TCP states are: SYN_SENT, SYN_RECV, ESTABLISHED, # FIN_WAIT, CLOSE_WAIT, LAST_ACK, TIME_WAIT, CLOSE, LISTEN. # # Replicate ESTABLISHED TIME_WAIT for TCP } # # General settings # General { # # Number of buckets in the caches: hash table # HashSize 8192 # # Maximum number of conntracks: # it must be >= $ cat /proc/sys/net/ipv4/netfilter/ip_conntrack_max # HashLimit 65535 # # Logfile # LogFile /var/log/conntrackd.log # # Lockfile # LockFile /var/lock/conntrack.lock # # Unix socket configuration # UNIX { Path /tmp/sync.sock Backlog 20 } # # Netlink socket buffer size # SocketBufferSize 262142 # # Increase the socket buffer up to maximum if required # SocketBufferSizeMaxGrown 655355 } # # Ignore traffic for a certain set of IP's: Usually # all the IP assigned to the firewall since local # traffic must be ignored, just forwarded connections # are worth to replicate # IgnoreTrafficFor { IPv4_address 127.0.0.1 # loopback IPv4_address 192.168.0.1 IPv4_address 192.168.1.1 IPv4_address 192.168.100.100 # dedicated link ip IPv4_address 192.168.0.100 # virtual IP 1 IPv4_address 192.168.1.100 # virtual IP 2 } # # Do not replicate certain protocol traffic # IgnoreProtocol { UDP ICMP IGMP VRRP # numeric numbers also valid }