Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

IPTABLES Hash is full, cannot add more elements #260

Closed
LaurenceJJones opened this issue Apr 13, 2023 · 4 comments
Closed

IPTABLES Hash is full, cannot add more elements #260

LaurenceJJones opened this issue Apr 13, 2023 · 4 comments

Comments

@LaurenceJJones
Copy link
Contributor

Just to add documentation and pin an issue to this bouncer.

Due to size of community blocklist and with added support of third party lists user may hit the default limit set by crowdsec-firewall-bouncer-iptables.

To resolve this issue the user must configure a bigger hash set. Open bouncer configuration located normally under /etc/crowdsec/bouncers/. Add the following config:

ipset_size: 131072
## this default 65536 * 2

This does not exists in the yaml by default so you MUST add it.

@LaurenceJJones LaurenceJJones pinned this issue Apr 13, 2023
@LaurenceJJones LaurenceJJones closed this as not planned Won't fix, can't repro, duplicate, stale Apr 13, 2023
@LaurenceJJones
Copy link
Contributor Author

@buixor Did you want to still explore increasing the default value?

@CERT-ARKEA
Copy link

the same opinion, increase the default value (with new blocklists, it is mandatory)

@LaurenceJJones
Copy link
Contributor Author

Reopening issue, to make sure we track any changes we make to cs-firewall

@mmetc
Copy link
Contributor

mmetc commented Sep 4, 2023

#324

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants