tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: IPfilter NAT and stalled TCP connexions



On 3/26/10 9:31 AM, Chuck Swiger wrote:
> Unless NetBSD has "sysctl net.inet.ip.ttl" set to less than 60, that low of a 
> timeout can be expected to be too short.  In fact, I'd suggest that setting 
> NAT timeouts to a minimum of least 5 minutes due to:

I don't think that sysctl is really a "time to live" in seconds as much
as the badly named IP header TTL value, which is decremented on each
forward through a router.  It's loop prevention not NAT related.

--Michael


Home | Main Index | Thread Index | Old Index