Community discussions

MikroTik App
 
borisk
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 97
Joined: Mon Jul 04, 2016 10:02 pm
Location: Nizhniy Tagil, Russia

Do I need connection tracking?

Sat Apr 01, 2017 11:15 am

Hello!

I have CCR-1016 used as core router. Only routing (IPv4, OSPF, BGP) and simple queues. No NAT, very few mangle rules for packet marking. System serves about 1.5Gbps. CPU is about 25%. For the time present is set connection tracking to "no". But may be I'm wrong and do I need connection tracking to "yes" or "auto"? I tried, get about 200k active connections, got scared and set it back to "no".

Regards,
Boris
 
User avatar
pukkita
Trainer
Trainer
Posts: 3051
Joined: Wed Dec 04, 2013 11:09 am
Location: Spain

Re: Do I need connection tracking?

Sat Apr 01, 2017 12:22 pm

It depends, for the duties you mentioned Connection Tracking is not needed.

But depending on your mangle it may be needed, do you use any criteria that would involve tracking a connection?

You may use auto, ROS will enable connection tracking if needed.
 
borisk
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 97
Joined: Mon Jul 04, 2016 10:02 pm
Location: Nizhniy Tagil, Russia

Re: Do I need connection tracking?

Sat Apr 01, 2017 12:37 pm

With mangle I only mark local traffic to put it in unlimited simple queue (if there is another way to not pass local traffic to user queue I will glad to hear about)
Yes, I tried auto and got about 200k connetions with a first 10-15 seconds. Router serves about 8k IP's so I suppose total count of active connection may be greater. As I see - the limit to connection is set to 1M. What will happen if it will be reached? What is perfomance impact for CCR-1036 with this number of connections?

Regards,
Boris
 
User avatar
pukkita
Trainer
Trainer
Posts: 3051
Joined: Wed Dec 04, 2013 11:09 am
Location: Spain

Re: Do I need connection tracking?

Sat Apr 01, 2017 3:13 pm

You could use fasttrack to make local traffic to bypass queues, conntrack, etc entirely.
 
borisk
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 97
Joined: Mon Jul 04, 2016 10:02 pm
Location: Nizhniy Tagil, Russia

Re: Do I need connection tracking?

Sat Apr 01, 2017 10:19 pm

Would You please give an example? Is connection tracking needed in this case?
 
User avatar
pukkita
Trainer
Trainer
Posts: 3051
Joined: Wed Dec 04, 2013 11:09 am
Location: Spain

Re: Do I need connection tracking?

Sun Apr 02, 2017 1:10 pm

Yes, but need either your config export, or the conditions for local traffic (in/out interfaces for example).

No, fasttrack bypasses conntrack
 
borisk
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 97
Joined: Mon Jul 04, 2016 10:02 pm
Location: Nizhniy Tagil, Russia

Re: Do I need connection tracking?

Sun Apr 02, 2017 7:10 pm

Hello!

address-list ACL_LOCAL serves list of my local networks

Regards,
Boris
 
borisk
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 97
Joined: Mon Jul 04, 2016 10:02 pm
Location: Nizhniy Tagil, Russia

Re: Do I need connection tracking?

Sun Apr 02, 2017 7:17 pm

Have read about fasttrack. Restriction for fasttrak is only TCP and UDP pakets, so, not all user packets will be fasttracked and may go to queues.
 
User avatar
ploquets
Member Candidate
Member Candidate
Posts: 162
Joined: Tue Nov 17, 2015 12:49 pm
Location: Uruguaiana, RS, Brazil
Contact:

Re: Do I need connection tracking?

Wed May 31, 2017 11:36 pm

If just mangle rules with Change mss are created to change MSS for PPPoE tunnels....

Do I need connection tracking?

Or I can create raw rules with no-track action for those which doesn't need NATing ?
Would the no-track action reduce CPU usage?

Thanks

Who is online

Users browsing this forum: ElmerHomero, Sirafim and 104 guests