Comment 3 for bug 1441363

Revision history for this message
Bjoern (bjoern-t) wrote :

Thanks for commenting. In terms of TW connection, I'm pretty confident that we don't have to fear out of order packets in a local network. I'm sure that we can intermittently fix this issue with upping the conntrack limit, but once it's hit already in a idle environment I fear we are going to hit it even more once it's used. Speaking of the environment, we have running RPC10 swift environments which do not have conntrack enabled so I find it really disturbing that we suddenly have one environment running with connection tracking. Which seemed to have been enabled accidentally by installing LXC, at least that was the difference compared to other environments since LXC includes lxc-net which needs iptables.