Hi,
i found that the astaro can be DoSed filling up the conntrack table.
The licensing doesn't allow to change the /proc/sys/net/ipv4/ip_conntrack_max kernel setting and there is no way to change the ip_conntrack timeouts (look for the kernel patch at http://www.stearns.org/pomlist/20030101-output/pom-extra.htm).
So any way to defend from a DoS filling up the conntrack table ?
Bye
This thread was automatically locked due to age.