I have CCR-1016 used as core router. Only routing (IPv4, OSPF, BGP) and simple queues. No NAT, very few mangle rules for packet marking. System serves about 1.5Gbps. CPU is about 25%. For the time present is set connection tracking to “no”. But may be I’m wrong and do I need connection tracking to “yes” or “auto”? I tried, get about 200k active connections, got scared and set it back to “no”.
With mangle I only mark local traffic to put it in unlimited simple queue (if there is another way to not pass local traffic to user queue I will glad to hear about)
Yes, I tried auto and got about 200k connetions with a first 10-15 seconds. Router serves about 8k IP’s so I suppose total count of active connection may be greater. As I see - the limit to connection is set to 1M. What will happen if it will be reached? What is perfomance impact for CCR-1036 with this number of connections?