Re: ip local port range

From: H. Peter Anvin (hpa@zytor.com)
Date: Wed Jun 21 2000 - 10:41:26 EST


Followup to: <3950AACD.EBFC323F@lifeline.nl>
By author: Bastiaan Bakker <Bastiaan.Bakker@lifeline.nl>
In newsgroup: linux.dev.kernel
>
> Hi,
>
> As has been dicussed on this list in April, Linux does not follow the
> IANA recommendation to use port number 49152 and higher for dynamic
> ports. Albert D. Cahalan suggested changing the current range of 1024
> till 4999 into 51024 till 514999. David Miller said 'Ok, this needs to
> be fixed then.' but Andi Kleen objected that the change would cause
> problems with poorly configured packes filters.
> Since then, it has been quiet about the topic, and the kernel has not
> been changed.
>

What's a better objection is that this range is just not enough. This
local-port range small enough to be painful on too many systems.

On my system, 2.4.0-test1-ac22-classzone, the default seems to be:

: tazenda 1 ; cat /proc/sys/net/ipv4/ip_local_port_range
32768 61000

Perhaps that should be changed to 49152/61000, but let's not keep the
braindamage of only having some 4000 local ports.

        -hpa

-- 
<hpa@transmeta.com> at work, <hpa@zytor.com> in private!
"Unix gives you enough rope to shoot yourself in the foot."
http://www.zytor.com/~hpa/puzzle.txt

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Fri Jun 23 2000 - 21:00:22 EST