Chapter 16: Controlling Access to the ER-1000
TR0190 Rev. B1
104
sharing applications. A number of parameters are available for tuning how connection tracking
is handled.
16.4.1
Connection Tracking Table Size
The size of the connection tracking table can be set. Allowed values are in the range from
4096 to 16384. A larger connection tracking table allows more connections to be maintained
without dropping older connections. Typically, the default size of 8192 is adequate for normal
operation and the setting should only be increased on devices with high levels of traffic and
many users.
CLI
The connection tracking table size is set by selecting the ‘firewall’ interface and setting the
‘conntrack.table_size’ parameter.
>
use firewall
firewall>
set conntrack.table_size=16384
Web GUI
The connection tracking table size is set with the “Conntrack Size” field on the “Connections”
sub-tab on the “Firewall” tab of the “Security” page (see Figure 48). This field is located under
the “Connection Tracking” heading.
16.4.2
Connection Tracking Timeout
The connection tracking timeout parameter allows you to flush connections that have been idle
for an extended period of time from the connection tracking table. This will help limit the
maximum required size of the connection tracking table. By default, this parameter is set to
3600 seconds (1 hour).
CLI
The connection tracking timeout is set by selecting the ‘firewall’ interface and setting the
‘conntrack.tcp_timeout_established’ parameter. The timeout is specified in seconds.
>
use firewall
firewall>
set conntrack.tcp_timeout_established=3600
Summary of Contents for EL-500
Page 20: ...Chapter 3 Using the Web Interface TR0190 Rev B1 20 Figure 8 Rebooting the EL 500...
Page 68: ...Chapter 11 Ethernet Interface Configuration TR0190 Rev B1 68 Figure 38 Wired DHCP settings...
Page 108: ...Chapter 16 Controlling Access to the ER 1000 TR0190 Rev B1 108 Figure 50 VAP ACL configuration...