Firewall Wizards mailing list archives

Linux ARPD -- neighbor table overflow


From: "Jeff Adam" <jadam () seark edu>
Date: Thu, 18 Mar 2004 17:12:07 -0600

I have run into a problem recently with arp table size limitation in the Linux kernel.

 

A bit of History

 I have been using the same box as a firewall for past couple of years and it has performed flawlessly Linux 2.4 / 
iptables but every couple of months the number of nodes on the LAN increases by 20 to 60 usually on the high end of 
that range we are already beyond 500 computers approaching 600 with plans to add 40 to 60 additional computers already 
being discussed. We have recently developed a problem with neighbor table overflows on the firewall during peak hours.

 

I believe I have the problem repaired I recompiled the kernel with arpd support and netlink and installed arpd and made 
some changes in /proc

Some other issues developed with arpd that were unexpected
 

the problem is all of the documentation I found on arpd was rather dated including one written in  2001 that claimed 
the package (arpd) was far beyond abandoned by the upstream maintainer. im sure networks with more than 256 nodes are 
not that uncommon. My question is what experiences have other readers of the list had with this issue and what other 
solutions are there besides arpd for this issue.

~*���e�,ڭ�&j)b� b������\"ͪݲ'�����Zn�(�m����z+�����r���������+-�w����{���j�l

Current thread: