1 .. SPDX-License-Identifier: GPL-2.0
3 ===================================
4 Netfilter Conntrack Sysfs variables
5 ===================================
7 /proc/sys/net/netfilter/nf_conntrack_* Variables:
8 =================================================
10 nf_conntrack_acct - BOOLEAN
11 - 0 - disabled (default)
14 Enable connection tracking flow accounting. 64-bit byte and packet
15 counters per flow are added.
17 nf_conntrack_buckets - INTEGER
18 Size of hash table. If not specified as parameter during module
19 loading, the default size is calculated by dividing total memory
20 by 16384 to determine the number of buckets. The hash table will
21 never have fewer than 1024 and never more than 262144 buckets.
22 This sysctl is only writeable in the initial net namespace.
24 nf_conntrack_checksum - BOOLEAN
26 - not 0 - enabled (default)
28 Verify checksum of incoming packets. Packets with bad checksums are
29 in INVALID state. If this is enabled, such packets will not be
30 considered for connection tracking.
32 nf_conntrack_count - INTEGER (read-only)
33 Number of currently allocated flow entries.
35 nf_conntrack_events - BOOLEAN
40 If this option is enabled, the connection tracking code will
41 provide userspace with connection tracking events via ctnetlink.
42 The default allocates the extension if a userspace program is
43 listening to ctnetlink events.
45 nf_conntrack_expect_max - INTEGER
46 Maximum size of expectation table. Default value is
47 nf_conntrack_buckets / 256. Minimum is 1.
49 nf_conntrack_frag6_high_thresh - INTEGER
52 Maximum memory used to reassemble IPv6 fragments. When
53 nf_conntrack_frag6_high_thresh bytes of memory is allocated for this
54 purpose, the fragment handler will toss packets until
55 nf_conntrack_frag6_low_thresh is reached.
57 nf_conntrack_frag6_low_thresh - INTEGER
60 See nf_conntrack_frag6_low_thresh
62 nf_conntrack_frag6_timeout - INTEGER (seconds)
65 Time to keep an IPv6 fragment in memory.
67 nf_conntrack_generic_timeout - INTEGER (seconds)
70 Default for generic timeout. This refers to layer 4 unknown/unsupported
73 nf_conntrack_icmp_timeout - INTEGER (seconds)
76 Default for ICMP timeout.
78 nf_conntrack_icmpv6_timeout - INTEGER (seconds)
81 Default for ICMP6 timeout.
83 nf_conntrack_log_invalid - INTEGER
84 - 0 - disable (default)
85 - 1 - log ICMP packets
87 - 17 - log UDP packets
88 - 33 - log DCCP packets
89 - 41 - log ICMPv6 packets
90 - 136 - log UDPLITE packets
91 - 255 - log packets of any protocol
93 Log invalid packets of a type specified by value.
95 nf_conntrack_max - INTEGER
96 Maximum number of allowed connection tracking entries. This value is set
97 to nf_conntrack_buckets by default.
98 Note that connection tracking entries are added to the table twice -- once
99 for the original direction and once for the reply direction (i.e., with
100 the reversed address). This means that with default settings a maxed-out
101 table will have a average hash chain length of 2, not 1.
103 nf_conntrack_tcp_be_liberal - BOOLEAN
104 - 0 - disabled (default)
107 Be conservative in what you do, be liberal in what you accept from others.
108 If it's non-zero, we mark only out of window RST segments as INVALID.
110 nf_conntrack_tcp_ignore_invalid_rst - BOOLEAN
111 - 0 - disabled (default)
114 If it's 1, we don't mark out of window RST segments as INVALID.
116 nf_conntrack_tcp_loose - BOOLEAN
118 - not 0 - enabled (default)
120 If it is set to zero, we disable picking up already established
123 nf_conntrack_tcp_max_retrans - INTEGER
126 Maximum number of packets that can be retransmitted without
127 received an (acceptable) ACK from the destination. If this number
128 is reached, a shorter timer will be started.
130 nf_conntrack_tcp_timeout_close - INTEGER (seconds)
133 nf_conntrack_tcp_timeout_close_wait - INTEGER (seconds)
136 nf_conntrack_tcp_timeout_established - INTEGER (seconds)
137 default 432000 (5 days)
139 nf_conntrack_tcp_timeout_fin_wait - INTEGER (seconds)
142 nf_conntrack_tcp_timeout_last_ack - INTEGER (seconds)
145 nf_conntrack_tcp_timeout_max_retrans - INTEGER (seconds)
148 nf_conntrack_tcp_timeout_syn_recv - INTEGER (seconds)
151 nf_conntrack_tcp_timeout_syn_sent - INTEGER (seconds)
154 nf_conntrack_tcp_timeout_time_wait - INTEGER (seconds)
157 nf_conntrack_tcp_timeout_unacknowledged - INTEGER (seconds)
160 nf_conntrack_timestamp - BOOLEAN
161 - 0 - disabled (default)
164 Enable connection tracking flow timestamping.
166 nf_conntrack_sctp_timeout_closed - INTEGER (seconds)
169 nf_conntrack_sctp_timeout_cookie_wait - INTEGER (seconds)
172 nf_conntrack_sctp_timeout_cookie_echoed - INTEGER (seconds)
175 nf_conntrack_sctp_timeout_established - INTEGER (seconds)
178 Default is set to (hb_interval * path_max_retrans + rto_max)
180 nf_conntrack_sctp_timeout_shutdown_sent - INTEGER (seconds)
183 nf_conntrack_sctp_timeout_shutdown_recd - INTEGER (seconds)
186 nf_conntrack_sctp_timeout_shutdown_ack_sent - INTEGER (seconds)
189 nf_conntrack_sctp_timeout_heartbeat_sent - INTEGER (seconds)
192 This timeout is used to setup conntrack entry on secondary paths.
193 Default is set to hb_interval.
195 nf_conntrack_udp_timeout - INTEGER (seconds)
198 nf_conntrack_udp_timeout_stream - INTEGER (seconds)
201 This extended timeout will be used in case there is an UDP stream
204 nf_conntrack_gre_timeout - INTEGER (seconds)
207 nf_conntrack_gre_timeout_stream - INTEGER (seconds)
210 This extended timeout will be used in case there is an GRE stream
213 nf_hooks_lwtunnel - BOOLEAN
214 - 0 - disabled (default)
217 If this option is enabled, the lightweight tunnel netfilter hooks are
218 enabled. This option cannot be disabled once it is enabled.
220 nf_flowtable_tcp_timeout - INTEGER (seconds)
223 Control offload timeout for tcp connections.
224 TCP connections may be offloaded from nf conntrack to nf flow table.
225 Once aged, the connection is returned to nf conntrack with tcp pickup timeout.
227 nf_flowtable_udp_timeout - INTEGER (seconds)
230 Control offload timeout for udp connections.
231 UDP connections may be offloaded from nf conntrack to nf flow table.
232 Once aged, the connection is returned to nf conntrack with udp pickup timeout.