{"id":74655,"date":"2020-03-19T08:42:34","date_gmt":"2020-03-19T05:42:34","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/kogda-linux-conntrack-vam-bolshe-ne-tovarishh"},"modified":"2020-03-19T08:42:34","modified_gmt":"2020-03-19T05:42:34","slug":"kogda-linux-conntrack-vam-bolshe-ne-tovarishh","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kogda-linux-conntrack-vam-bolshe-ne-tovarishh","title":{"rendered":"Kur Linux conntrack nuk \u00ebsht\u00eb m\u00eb shoku juaj","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Kur Linux conntrack nuk \u00ebsht\u00eb m\u00eb shoku juaj\" src=\"\/wp-content\/uploads\/2020\/03\/588a169e5cfe0714694b8d7ff03985d1.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Urmarja e lidhjeve (\u201cconntrack\u201d) \u00ebsht\u00eb nj\u00eb funksion ky\u00e7 i kafazit rrjetor t\u00eb b\u00ebrtham\u00ebs Linux. Ajo lejon b\u00ebrtham\u00ebn t\u00eb ndjek\u00eb t\u00eb gjitha lidhjet rrjetore logjike ose rrjedhat dhe k\u00ebshtu t\u00eb identifikoj\u00eb t\u00eb gjitha paketat q\u00eb p\u00ebrb\u00ebjn\u00eb \u00e7do rrjedh\u00eb, n\u00eb m\u00ebnyr\u00eb q\u00eb ato t\u00eb munden t\u00eb p\u00ebrpunohen s\u00eb bashku n\u00eb m\u00ebnyr\u00eb sekuenciale.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p>Conntrack \u00ebsht\u00eb nj\u00eb funksion i r\u00ebnd\u00ebsish\u00ebm i b\u00ebrtham\u00ebs, i cili p\u00ebrdoret n\u00eb disa raste t\u00eb r\u00ebnd\u00ebsishme:<\/p>\n<p><\/p>\n<ul>\n<li>NAT mb\u00ebshtetet n\u00eb informacionin nga conntrack, prandaj mund t\u00eb p\u00ebrpunoj\u00eb nj\u00eblloj t\u00eb gjitha paketat nga nj\u00eb rrjedh\u00eb. P\u00ebr shembull, kur nj\u00eb pod i drejtohet nj\u00eb sh\u00ebrbimi Kubernetes, balancuesi i ngarkes\u00ebs kube-proxy p\u00ebrdor NAT p\u00ebr t\u00eb drejtuar trafikun n\u00eb nj\u00eb pod t\u00eb caktuar brenda klustrit. Conntrack regjistron se p\u00ebr nj\u00eb lidhje t\u00eb caktuar, t\u00eb gjitha paketat n\u00eb IP-n\u00eb e sh\u00ebrbimit duhet t\u00eb d\u00ebrgohen te po ai pod, dhe paketat q\u00eb kthehen nga pod-i pastrues duhet t\u00eb drejtohen prapa nga NAT te pod-i nga ku erdhi k\u00ebrkesa.<\/li>\n<li>Firewall-et me ndjekje gjendjeje, si Calico, mb\u00ebshteten n\u00eb informacionin nga conntrack p\u00ebr t\u00eb shtuar trafikun \u201cp\u00ebrgjigj\u00ebs\u201d n\u00eb list\u00ebn e bardh\u00eb. Kjo ju lejon t\u00eb shkruani nj\u00eb politik\u00eb rrjeti q\u00eb thot\u00eb: \"lejo pod-in tim t\u00eb lidhet me \u00e7do IP t\u00eb larg\u00ebt\" pa pasur nevoj\u00eb t\u00eb shkruani nj\u00eb politik\u00eb p\u00ebr t\u00eb lejuar n\u00eb m\u00ebnyr\u00eb eksplicite trafikun p\u00ebrgjigj\u00ebs. (Pa k\u00ebt\u00eb, do t\u00eb duhej t\u00eb shtonit nj\u00eb rregull shum\u00eb m\u00eb pak t\u00eb sigurt \"lejo paketat n\u00eb pod-in tim nga \u00e7do IP\").<\/li>\n<\/ul>\n<p><\/p>\n<p>P\u00ebr m\u00eb tep\u00ebr, conntrack zakonisht rrit performanc\u00ebn e sistemit (duke reduktuar konsumin e koh\u00ebs s\u00eb procesorit dhe vones\u00ebn e paketave), pasi vet\u00ebm paketa e par\u00eb n\u00eb nj\u00eb rrjedh\u00eb<br \/>\nduhet t\u00eb kaloj\u00eb p\u00ebrpunimin e plot\u00eb t\u00eb kafazit t\u00eb rrjetit p\u00ebr t\u00eb p\u00ebrcaktuar se \u00e7far\u00eb duhet t\u00eb b\u00ebj\u00eb me t\u00eb. Shihni postimin \"<noindex><a rel=\"nofollow\" href=\"https:\/\/www.tigera.io\/blog\/comparing-kube-proxy-modes-iptables-or-ipvs\/\">Krahasimi i modeleve kube-proxy<\/a><\/noindex>\u2019, p\u00ebr t\u00eb par\u00eb nj\u00eb shembull se si funksionon kjo.<\/p>\n<p><\/p>\n<p>Megjithat\u00eb, conntrack ka kufizimet e veta\u2026<\/p>\n<p><\/p>\n<h3 id=\"itak-gde-vse-poshlo-ne-tak\">Pra, ku shkoi gjith\u00e7ka keq?<\/h3>\n<p><\/p>\n<p>Tavolina conntrack ka nj\u00eb maksimum t\u00eb konfiguruesh\u00ebm, dhe n\u00ebse ajo mbushet, lidhjet zakonisht fillojn\u00eb t\u00eb refuzohen ose t\u00eb priten. P\u00ebr t\u00eb p\u00ebrpunuar trafikun e shumic\u00ebs s\u00eb aplikacioneve, tavolina zakonisht ka mjaft hap\u00ebsir\u00eb t\u00eb lir\u00eb dhe kjo kurr\u00eb nuk do t\u00eb b\u00ebhet nj\u00eb problem. Megjithat\u00eb, ka disa skenar\u00eb kur ia vlen t\u00eb mendoni p\u00ebr p\u00ebrdorimin e tavolines conntrack:<\/p>\n<p><\/p>\n<ul>\n<li>Rast\u00ebsia m\u00eb e dukshme \u00ebsht\u00eb n\u00ebse serveri juaj p\u00ebrpunon nj\u00eb num\u00ebr t\u00eb jasht\u00ebzakonsh\u00ebm lidhjesh aktive n\u00eb t\u00eb nj\u00ebjt\u00ebn koh\u00eb. P\u00ebr shembull, n\u00ebse tabela juaj conntrack \u00ebsht\u00eb e konfiguruar p\u00ebr 128k regjistrime, por keni m\u00eb shum\u00eb se 128k lidhje t\u00eb nj\u00ebkohshme, sigurisht q\u00eb do t\u00eb hasni nj\u00eb problem!<\/li>\n<li>Nj\u00eb rast pak m\u00eb pak i duksh\u00ebm \u00ebsht\u00eb n\u00ebse serveri juaj p\u00ebrpunon nj\u00eb num\u00ebr t\u00eb madh lidhjesh n\u00eb sekond\u00eb. Edhe n\u00ebse lidhjet jan\u00eb t\u00eb p\u00ebrkohshme, ato vazhdojn\u00eb t\u00eb gjurmohen nga Linux p\u00ebr nj\u00eb periudh\u00eb t\u00eb caktuar kohe (n\u00eb m\u00ebnyr\u00eb standarde 120 sekonda). P\u00ebr shembull, n\u00ebse tabela juaj conntrack \u00ebsht\u00eb e konfiguruar p\u00ebr 128 mij\u00eb regjistrime dhe p\u00ebrpiqeni t\u00eb p\u00ebrpunoni 1100 lidhje n\u00eb sekond\u00eb, ato do t\u00eb tejkalojn\u00eb madh\u00ebsin\u00eb e tabel\u00ebs conntrack, edhe n\u00ebse lidhjet jan\u00eb shum\u00eb t\u00eb shkurtra (128k \/ 120s = 1092 lidhje \/ s).<\/li>\n<\/ul>\n<p><\/p>\n<p>Ka disa lloje aplikacionesh ni\u00e7\u00eb q\u00eb bien n\u00eb k\u00ebto kategori. P\u00ebrve\u00e7 k\u00ebsaj, n\u00ebse keni shum\u00eb kund\u00ebrshtar\u00eb, mbushja e tabel\u00ebs conntrack t\u00eb serverit tuaj me shum\u00eb lidhje gjysm\u00eb t\u00eb hapura mund t\u00eb p\u00ebrdoret si nj\u00eb sulm nga lart t\u00eb tipo \u00abrefuzim sh\u00ebrbimi\u00bb (DOS). N\u00eb t\u00eb dyja rastet, conntrack mund t\u00eb b\u00ebhet pika e ngusht\u00eb q\u00eb kufizon sistemin tuaj. N\u00eb disa raste, rregullimi i parametrave t\u00eb tabel\u00ebs conntrack mund t\u00eb jet\u00eb i mjaftuesh\u00ebm p\u00ebr t\u00eb p\u00ebrmbushur nevojat tuaja \u2014 duke rritur madh\u00ebsin\u00eb ose shkurtuar koh\u00ebt e skadimit conntrack (por n\u00ebse e b\u00ebni k\u00ebt\u00eb gabim, do t\u00eb p\u00ebrballeni me v\u00ebshtir\u00ebsi t\u00eb m\u00ebdha). P\u00ebr raste t\u00eb tjera, do t\u00eb duhet t\u00eb anashkaloni conntrack p\u00ebr trafikun agresiv.<\/p>\n<p><\/p>\n<h4 id=\"realnyy-primer\">Nj\u00eb shembull real<\/h4>\n<p><\/p>\n<p>T\u00eb japim nj\u00eb shembull konkret: nj\u00eb ofrues i madh t\u00eb sh\u00ebrbimeve SaaS me t\u00eb cilin kemi punuar kishte nj\u00eb s\u00ebr\u00eb serverash memcached n\u00eb hosta (jo n\u00eb makinat virtuale), secili prej t\u00eb cil\u00ebve p\u00ebrpunonte m\u00eb shum\u00eb se 50K lidhje t\u00eb p\u00ebrkohshme n\u00eb sekond\u00eb.<\/p>\n<p><\/p>\n<p>Ata eksperimentuan me konfigurimin e conntrack, rrit\u00ebn madh\u00ebsit\u00eb e tabelave dhe shkurtuan koh\u00ebn e gjurmimit, por konfigurimi ishte i pasigurt, konsumimi i RAM ishte rritur ndjesh\u00ebm, q\u00eb ishte nj\u00eb problem (rreth GB!), dhe lidhjet ishin aq t\u00eb shkurtra saq\u00eb conntrack nuk krijonte p\u00ebrfitimin e tij t\u00eb zakonsh\u00ebm n\u00eb performanc\u00eb (reduktimin e konsumit t\u00eb CPU ose vonesave t\u00eb paketave).<\/p>\n<p><\/p>\n<p>Si si ndihmoi, ata iu drejtuan Calico. Politikat e rrjetit t\u00eb Calico lejojn\u00eb q\u00eb t\u00eb mos p\u00ebrdoret conntrack p\u00ebr nj\u00eb lloj t\u00eb caktuar trafiku (duke p\u00ebrdorur opsionin doNotTrack p\u00ebr politikat). Kjo iu sigurua atyre nivelin e nevojsh\u00ebm t\u00eb performanc\u00ebs plus nj\u00eb nivel shtes\u00eb sigurie q\u00eb ofrohet nga Calico.<\/p>\n<p><\/p>\n<h4 id=\"na-chto-pridetsya-poyti-chtoby-oboyti-conntrack\">\u00c7far\u00eb do t\u00eb b\u00ebhet p\u00ebr t\u00eb anashkaluar conntrack?<\/h4>\n<p><\/p>\n<ul>\n<li>Politikat e rrjetit do-not-track zakonisht duhet t\u00eb jen\u00eb simetrike. N\u00eb rastin e ofruesit SaaS: aplikacionet e tyre funksiononin brenda nj\u00eb zone t\u00eb mbrojtur dhe p\u00ebr shkak t\u00eb politik\u00ebs s\u00eb rrjetit, ata mund t\u00eb shtonin n\u00eb list\u00ebn e bardh\u00eb trafikun nga aplikacione t\u00eb tjera specifike q\u00eb kishte leje p\u00ebr t'u aksesuar n\u00eb memcached.<\/li>\n<li>Politika do-not-track nuk merr parasysh drejtimin e lidhjes. Prandaj, n\u00eb rast t\u00eb nj\u00eb sulmi n\u00eb serverin memcached, teorikisht mund t\u00eb p\u00ebrpiqet t\u00eb lidhet me ndonj\u00eb nga klient\u00ebt memcached, n\u00ebse ai p\u00ebrdor portin e duhur t\u00eb origjin\u00ebs. Megjithat\u00eb, n\u00ebse e keni p\u00ebrcaktuar sakt\u00eb politik\u00ebn e rrjetit p\u00ebr klient\u00ebt tuaj memcached, k\u00ebto p\u00ebrpjekje lidhen ende p\u00ebr t'u refuzuar nga ana e klientit.<\/li>\n<li>Politika do-not-track aplikohet p\u00ebr \u00e7do paket\u00eb, n\u00eb kund\u00ebrshtim me politikat e zakonshme, t\u00eb cilat aplikohen vet\u00ebm p\u00ebr paket\u00ebn e par\u00eb nga rrjedha. Kjo mund ta rris\u00eb shpenzimin e burimeve CPU p\u00ebr nj\u00eb paket\u00eb, pasi p\u00ebr \u00e7do paket\u00eb duhet t\u00eb aplikohet politika. Por p\u00ebr lidhjet afatshkurtra, ky shpenzim kompensohet nga ulja e shpenzimeve p\u00ebr trajtimin e conntrack. P\u00ebr shembull, n\u00eb rastin e ofruesit SaaS, numri i paketave p\u00ebr \u00e7do lidhje ishte shum\u00eb i vog\u00ebl, k\u00ebshtu q\u00eb shpenzimi shtes\u00eb i burimeve CPU gjat\u00eb aplikimit t\u00eb politikave p\u00ebr \u00e7do paket\u00eb ishte i arsyesh\u00ebm.<\/li>\n<\/ul>\n<p><\/p>\n<h4 id=\"pristupim-k-testam\">Le t\u00eb fillojm\u00eb testet<\/h4>\n<p><\/p>\n<p>Kemi kryer nj\u00eb test n\u00eb nj\u00eb pod me nj\u00eb server memcached dhe shum\u00eb pod t\u00eb klient\u00ebve memcached t\u00eb ekzekutuar n\u00eb nodet e larg\u00ebta, n\u00eb m\u00ebnyr\u00eb q\u00eb t\u00eb mund t\u00eb ekzekutonim nj\u00eb num\u00ebr shum\u00eb t\u00eb madh lidhjesh n\u00eb sekond\u00eb. Serveri me podin e serverit memcached kishte 8 b\u00ebrthama dhe 512k regjistrime n\u00eb tabel\u00ebn conntrack (madh\u00ebsia standarde e konfigurimit t\u00eb tabel\u00ebs p\u00ebr hostin).<br \/>\nNe mat\u00ebm ndryshimin n\u00eb performanc\u00eb midis: pa politik\u00eb rrjeti; me politik\u00ebn e zakonshme t\u00eb Calico; dhe politik\u00ebn Calico do-not-track.<\/p>\n<p><\/p>\n<p>P\u00ebr testin e par\u00eb ne vendos\u00ebm numrin e lidhjeve deri n\u00eb 4.000 n\u00eb sekond\u00eb, prandaj mund\u00ebm t\u00eb p\u00ebrq\u00ebndrohemi n\u00eb ndryshimin e konsumit t\u00eb CPU-s\u00eb. K\u00ebtu nuk kishte ndryshime t\u00eb r\u00ebnd\u00ebsishme midis munges\u00ebs s\u00eb politikave dhe politikave t\u00eb zakonshme, por politika do-not-track rriti konsumimin e CPU-s\u00eb me rreth 20%:<\/p>\n<p>\n<img decoding=\"async\" alt=\"Kur Linux conntrack nuk \u00ebsht\u00eb m\u00eb shoku juaj\" src=\"\/wp-content\/uploads\/2020\/03\/6762772cb8e5f089a3ed444aff8cb8f4.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>N\u00eb testin e dyt\u00eb, ne e lansuam sa m\u00eb shum\u00eb lidhje sa mund\u00ebn klient\u00ebt tan\u00eb dhe mat\u00ebm numrin maksimal t\u00eb lidhjeve n\u00eb sekond\u00eb q\u00eb serveri yn\u00eb memcached mund t\u00eb p\u00ebrballonte. Si\u00e7 pritej, n\u00eb rastin 'pa politika' dhe 'politika e zakonshme' t\u00eb dy arrit\u00ebn limitin e conntrack mbi 4,000 lidhje n\u00eb sekond\u00eb (512k \/ 120s = 4,369 lidhje\/s). Me politik\u00ebn do-not-track, klient\u00ebt tan\u00eb d\u00ebrguan 60,000 lidhje n\u00eb sekond\u00eb pa asnj\u00eb problem. Jemi t\u00eb sigurt se do t\u00eb mund t\u00eb rritnim k\u00ebt\u00eb num\u00ebr, duke lidhur m\u00eb shum\u00eb klient\u00eb, por mendojm\u00eb se k\u00ebto numra jan\u00eb t\u00eb mjaftueshme p\u00ebr t\u00eb ilustruar mesazhin e k\u00ebtij artikulli!<\/p>\n<p>\n<img decoding=\"async\" alt=\"Kur Linux conntrack nuk \u00ebsht\u00eb m\u00eb shoku juaj\" src=\"\/wp-content\/uploads\/2020\/03\/f3beeb1793a3158018274079da953a2c.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h4 id=\"zaklyuchenie\">P\u00ebrfundim<\/h4>\n<p><\/p>\n<p>Conntrack \u00ebsht\u00eb nj\u00eb funksion i r\u00ebnd\u00ebsish\u00ebm i b\u00ebrtham\u00ebs. Ai e b\u00ebn pun\u00ebn e tij shk\u00eblqyesh\u00ebm. Shpesh p\u00ebrdoret nga komponent\u00ebt ky\u00e7 t\u00eb sistemit. Sidoqoft\u00eb, n\u00eb disa skenar\u00eb t\u00eb caktuar, ngarkesa p\u00ebr shkak t\u00eb conntrack e tejkalon p\u00ebrfitimet e zakonshme q\u00eb ai ofron. N\u00eb k\u00ebt\u00eb skenar, politikat rrjetore Calico mund t\u00eb p\u00ebrdoren p\u00ebr t\u00eb \u00e7aktivizuar selektivisht p\u00ebrdorimin e conntrack duke e rritur k\u00ebshtu nivelin e siguris\u00eb rrjetore. P\u00ebr t\u00eb gjith\u00eb trafikun tjet\u00ebr, conntrack vazhdon t\u00eb jet\u00eb shoku juaj!<\/p>\n<p><\/p>\n<h2 id=\"takzhe-chitayte-drugie-stati-v-nashem-bloge\">Lexoni gjithashtu artikuj t\u00eb tjer\u00eb n\u00eb blogun ton\u00eb:<\/h2>\n<p><\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/nixys\/blog\/473578\/\">Nd\u00ebrtimi i moduleve dinamike p\u00ebr Nginx<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/nixys\/blog\/473014\/\">Hyrja n\u00eb autorizimin e Kubernetes t\u00eb Hashicorp Consul<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/nixys\/blog\/426543\/\">Backup-et Stateful n\u00eb Kubernetes<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/nixys\/blog\/424717\/\">Backup i nj\u00eb numri t\u00eb madh projektesh web t\u00eb larmishme<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/nixys\/blog\/347526\/\">Telegram-boti p\u00ebr Redmine. Si ta thjeshtoni jet\u00ebn tuaj dhe t\u00eb tjer\u00ebve<\/a><\/noindex><\/li>\n<\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/nixys\/blog\/492686\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u043d\u0438\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439 (\u201cconntrack\u201d) \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0435\u0439 \u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u0441\u0442\u0435\u043a\u0430 \u044f\u0434\u0440\u0430 Linux. \u041e\u043d\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u044f\u0434\u0440\u0443 \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u0442\u044c \u0432\u0441\u0435 \u043b\u043e\u0433\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0441\u0435\u0442\u0435\u0432\u044b\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f \u0438\u043b\u0438 \u043f\u043e\u0442\u043e\u043a\u0438 \u0438 \u0442\u0435\u043c \u0441\u0430\u043c\u044b\u043c \u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0432\u0441\u0435 \u043f\u0430\u043a\u0435\u0442\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0442 \u043a\u0430\u0436\u0434\u044b\u0439 \u043f\u043e\u0442\u043e\u043a, \u0447\u0442\u043e\u0431\u044b \u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0431\u044b\u043b\u043e \u043f\u043e\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u043d\u043e \u043e\u0431\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0442\u044c \u0432\u043c\u0435\u0441\u0442\u0435. Conntrack \u2014 \u044d\u0442\u043e \u0432\u0430\u0436\u043d\u0430\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u044f\u0434\u0440\u0430, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0441\u043d\u043e\u0432\u043d\u044b\u0445 \u0441\u043b\u0443\u0447\u0430\u044f\u0445: NAT \u043e\u043f\u0438\u0440\u0430\u0435\u0442\u0441\u044f \u043d\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0442 \u0441onntrack, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":74656,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-74655","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u043d\u0438\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439 (\u201cconntrack\u201d) \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kogda-linux-conntrack-vam-bolshe-ne-tovarishh\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u043e\u0433\u0434\u0430 Linux conntrack \u0432\u0430\u043c \u0431\u043e\u043b\u044c\u0448\u0435 \u043d\u0435 \u0442\u043e\u0432\u0430\u0440\u0438\u0449 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u043d\u0438\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439 (\u201cconntrack\u201d) \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kogda-linux-conntrack-vam-bolshe-ne-tovarishh\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-03-19T05:42:34+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-19T05:42:34+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Kur Linux conntrack nuk \u00ebsht\u00eb m\u00eb shoku juaj | ProHoster","description":"Ndjekja e lidhjeve (\u201cconntrack\u201d) \u00ebsht\u00eb.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kogda-linux-conntrack-vam-bolshe-ne-tovarishh","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u043e\u0433\u0434\u0430 Linux conntrack \u0432\u0430\u043c \u0431\u043e\u043b\u044c\u0448\u0435 \u043d\u0435 \u0442\u043e\u0432\u0430\u0440\u0438\u0449 | ProHoster","og:description":"\u041e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u043d\u0438\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439 (\u201cconntrack\u201d) \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kogda-linux-conntrack-vam-bolshe-ne-tovarishh","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-03-19T05:42:34+00:00","article:modified_time":"2020-03-19T05:42:34+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"74655","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 18:10:25","updated":"2022-10-05 19:52:30","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/74655","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=74655"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/74655\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/74656"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=74655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=74655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=74655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}