mirror of
https://github.com/vincentmli/bpfire.git
synced 2026-04-14 04:52:59 +02:00
suricata: Use 64MB of RAM for defragmentation
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org> Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
This commit is contained in:
committed by
Stefan Schantl
parent
83b576c892
commit
7eed864c93
@@ -474,27 +474,13 @@ host-os-policy:
|
||||
# Defrag settings:
|
||||
|
||||
defrag:
|
||||
memcap: 32mb
|
||||
memcap: 64mb
|
||||
hash-size: 65536
|
||||
trackers: 65535 # number of defragmented flows to follow
|
||||
max-frags: 65535 # number of fragments to keep (higher than trackers)
|
||||
prealloc: yes
|
||||
timeout: 60
|
||||
|
||||
# Enable defrag per host settings
|
||||
# host-config:
|
||||
#
|
||||
# - dmz:
|
||||
# timeout: 30
|
||||
# address: [192.168.1.0/24, 127.0.0.0/8, 1.1.1.0/24, 2.2.2.0/24, "1.1.1.1", "2.2.2.2", "::1"]
|
||||
#
|
||||
# - lan:
|
||||
# timeout: 45
|
||||
# address:
|
||||
# - 192.168.0.0/24
|
||||
# - 192.168.10.0/24
|
||||
# - 172.16.14.0/24
|
||||
|
||||
# Flow settings:
|
||||
# By default, the reserved memory (memcap) for flows is 32MB. This is the limit
|
||||
# for flow allocation inside the engine. You can change this value to allow
|
||||
|
||||
Reference in New Issue
Block a user