Running out of sessions: DMZplus on Pace 5031nv with (recent?) 10.5.6.529707-att firmware

Internet access discussion, including Fusion, IP Broadband, and Gigabit Fiber!
2 posts Page 1 of 1
by scottsakai » Mon Jun 18, 2018 11:40 pm
I run my FTTN Pace 5031nv in DMZ+ mode and forward everything to a Linux host. This arrangement has served me well, aside from some minor annoyances (like intercepting NTP).

Sometime last week, I lost connectivity and found that my RG lost its firewall and DHCP configuration, causing my Linux host to lose its DMZ+ status. This coincided with what appeared to be an update in the early morning. No problem, bounce the RG, reconfigure DMZ+ and go back to business.

Since then, I've been having frequent interruptions while playing online games, in particular, services based off of P2P UDP. A tcpdump on the Linux host's interface connected to the RG shows that the inbound (from the internet) service-related UDP streams just stop, causing a disconnect message in the affected game.

Digging further, I found that despite all efforts to disable / bypass the RG's firewall, it is still connection-state tracking, and that its number of session slots is small -- 8112 to be exact. (compare to 65536 on the Linux host)

My first observation is that there is a giant discrepancy between the RG's reported session usage and the Linux host's session usage:

Code: Select all

$ curl  --silent 'http://192.168.1.254/xslt?PAGE=C_5_5' | grep -P -o 'Total sessions in use:\s*\d+'
Total sessions in use: 3292

Code: Select all

# conntrack -C
349
My second observation is that minor peaks in the background radiation from the Internet can consume all of the session slots on the RG, effectively creating a denial of service.

Is there any way to increase the session limit, or preferably, bypass the connection-state tracking for DMZ+?

FWIW, my timeouts are set to the defaults:
600s for UDP
86400s for TCP
by Bmcd » Sun Jun 24, 2018 7:24 pm
If you figure out a solution for this, or a replacement modem, please post a reply on this thread. I’m having the same problem myself and it is very annoying to have to reset the router to clear the table. Thanks!
2 posts Page 1 of 1

Who is online

In total there are 27 users online :: 1 registered, 0 hidden and 26 guests (based on users active over the past 5 minutes)
Most users ever online was 999 on Mon May 10, 2021 1:02 am

Users browsing this forum: Google [Bot] and 26 guests