{"id":74655,"date":"2020-03-19T08:42:34","date_gmt":"2020-03-19T05:42:34","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/kogda-linux-conntrack-vam-bolshe-ne-tovarishh"},"modified":"2020-03-19T08:42:34","modified_gmt":"2020-03-19T05:42:34","slug":"kogda-linux-conntrack-vam-bolshe-ne-tovarishh","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kogda-linux-conntrack-vam-bolshe-ne-tovarishh","title":{"rendered":"Kur Linux conntrack nuk \u00ebsht\u00eb m\u00eb nj\u00eb mik p\u00ebr ju","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Kur Linux conntrack nuk \u00ebsht\u00eb m\u00eb nj\u00eb mik p\u00ebr ju\" src=\"\/wp-content\/uploads\/2020\/03\/588a169e5cfe0714694b8d7ff03985d1.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Ndjekja e lidhjeve (\u201cconntrack\u201d) \u00ebsht\u00eb nj\u00eb funksion kryesor i grumbullit t\u00eb rrjetit n\u00eb b\u00ebrtham\u00ebn Linux. Ajo i lejon b\u00ebrtham\u00ebs t\u00eb ndjek\u00eb t\u00eb gjitha lidhjet ose rrjedhat logjike t\u00eb rrjetit dhe n\u00eb k\u00ebt\u00eb m\u00ebnyr\u00eb t\u00eb identifikoj\u00eb t\u00eb gjith\u00eb paketat q\u00eb p\u00ebrb\u00ebjn\u00eb \u00e7do rrjedh, n\u00eb m\u00ebnyr\u00eb q\u00eb ato t\u00eb mund t\u00eb p\u00ebrpunohen s\u00eb bashku.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p>Conntrack \u00ebsht\u00eb nj\u00eb funksion i r\u00ebnd\u00ebsish\u00ebm i b\u00ebrtham\u00ebs, q\u00eb p\u00ebrdoret n\u00eb disa raste kryesore:<\/p>\n<p><\/p>\n<ul>\n<li>NAT mb\u00ebshtetet n\u00eb informacionin nga conntrack, k\u00ebshtu q\u00eb ai mund t\u00eb trajtoj\u00eb n\u00eb m\u00ebnyr\u00eb t\u00eb nj\u00ebjt\u00eb t\u00eb gjitha paketat nga nj\u00eb rrjedh. P\u00ebr shembull, kur nj\u00eb pod i drejtohet nj\u00eb sh\u00ebrbimi Kubernetes, balancuesi i ngarkes\u00ebs kube-proxy p\u00ebrdor NAT p\u00ebr t\u00eb drejtuar trafikun n\u00eb nj\u00eb pod t\u00eb caktuar brenda klasterit. Conntrack regjistron se p\u00ebr nj\u00eb lidhje t\u00eb caktuar, t\u00eb gjitha paketat q\u00eb d\u00ebrgohen n\u00eb IP-n\u00eb e sh\u00ebrbimit duhet t\u00eb d\u00ebrgohen n\u00eb t\u00eb nj\u00ebjtin pod, dhe se paketat q\u00eb kthehen nga pod-i i prapavij\u00ebs duhet t\u00eb kthehen p\u00ebrs\u00ebri nga NAT n\u00eb pod-in nga i cili erdhi k\u00ebrkesa.<\/li>\n<li>Firewally me mbik\u00ebqyrje t\u00eb gjendjes, si Calico, bazohen n\u00eb informacionin nga conntrack p\u00ebr t\u00eb shtuar trafikun \"p\u00ebrgjigj\u00ebs\" n\u00eb list\u00ebn e bardh\u00eb. Kjo ju lejon t\u00eb shkruani nj\u00eb politik\u00eb rrjeti q\u00eb thot\u00eb: \"lejoni pod-in tim t\u00eb lidhet me \u00e7do adres\u00eb IP t\u00eb larg\u00ebt\" pa pasur nevoj\u00eb t\u00eb shkruani nj\u00eb politik\u00eb p\u00ebr t\u00eb lejuar p\u00ebrgjigjen e trafikut. (Pa k\u00ebt\u00eb, do t\u00eb duhej t\u00eb shtonit nj\u00eb rregull shum\u00eb m\u00eb pak t\u00eb sigurt \"lejoni paketa n\u00eb pod-in tim nga \u00e7do IP.\")<\/li>\n<\/ul>\n<p><\/p>\n<p>P\u00ebr m\u00eb tep\u00ebr, conntrack zakonisht rrit performanc\u00ebn e sistemit (duke reduktuar konsumimin e koh\u00ebs s\u00eb procesorit dhe vonesat e paketave), pasi vet\u00ebm paketi i par\u00eb n\u00eb nj\u00eb rrjedh\u00eb<br \/>\nduhet t\u00eb kaloj\u00eb p\u00ebrpunimin e plot\u00eb t\u00eb stack-ut t\u00eb rrjetit p\u00ebr t\u00eb p\u00ebrcaktuar \u00e7far\u00eb t\u00eb b\u00ebj\u00eb me t\u00eb. Shikoni postimin \"<noindex><a rel=\"nofollow\" href=\"https:\/\/www.tigera.io\/blog\/comparing-kube-proxy-modes-iptables-or-ipvs\/\">Krahasimi i m\u00ebnyrave kube-proxy<\/a><\/noindex>\", p\u00ebr t\u00eb par\u00eb nj\u00eb shembull t\u00eb k\u00ebsaj n\u00eb pun\u00eb.<\/p>\n<p><\/p>\n<p>Megjithat\u00eb, conntrack ka kufizimet e veta\u2026<\/p>\n<p><\/p>\n<h3 id=\"itak-gde-vse-poshlo-ne-tak\">Pra, ku gjith\u00e7ka shkoi keq?<\/h3>\n<p><\/p>\n<p>Tabeli conntrack ka nj\u00eb madh\u00ebsi maksimale t\u00eb konfigurueshme dhe, n\u00ebse ajo mbushet, lidhjet zakonisht fillojn\u00eb t\u00eb refuzohen ose t\u00eb nd\u00ebrpriten. P\u00ebr t\u00eb menaxhuar trafikun e shumic\u00ebs s\u00eb aplikacioneve, tabela zakonisht ka mjaft hap\u00ebsir\u00eb t\u00eb lir\u00eb dhe kjo kurr\u00eb nuk do t\u00eb b\u00ebhet nj\u00eb problem. Megjithat\u00eb, ka disa skenar\u00eb ku ia vlen t\u00eb mendoni p\u00ebr p\u00ebrdorimin e tabel\u00ebs conntrack:<\/p>\n<p><\/p>\n<ul>\n<li>Rasti m\u00eb i duksh\u00ebm \u00ebsht\u00eb n\u00ebse serveri juaj po p\u00ebrpunon nj\u00eb num\u00ebr jasht\u00ebzakonisht t\u00eb madh lidhjesh aktive t\u00eb nj\u00ebkohshme. P\u00ebr shembull, n\u00ebse tabela juaj conntrack \u00ebsht\u00eb e konfiguruar p\u00ebr 128k regjistrime, por keni &gt; 128k lidhje t\u00eb nj\u00ebkohshme, me siguri do t\u00eb p\u00ebrballeni me nj\u00eb problem!<\/li>\n<li>Nj\u00eb rast pak m\u00eb pak i duksh\u00ebm \u00ebsht\u00eb n\u00ebse serveri juaj po p\u00ebrpunon nj\u00eb num\u00ebr t\u00eb madh lidhjesh n\u00eb sekond\u00eb. Edhe n\u00ebse lidhjet jan\u00eb t\u00eb shkurtra, ato vazhdojn\u00eb t\u00eb ndiqen nga Linux p\u00ebr nj\u00eb periudh\u00eb t\u00eb caktuar kohe (n\u00eb m\u00ebnyr\u00eb standarde 120s). P\u00ebr shembull, n\u00ebse tabela juaj conntrack \u00ebsht\u00eb e konfiguruar p\u00ebr 128 mij\u00eb regjistrime dhe po p\u00ebrpiqeni t\u00eb p\u00ebrpunoni 1100 lidhje n\u00eb sekond\u00eb, ato do ta kalojn\u00eb madh\u00ebsin\u00eb e tabel\u00ebs conntrack, madje edhe n\u00ebse lidhjet jan\u00eb shum\u00eb t\u00eb shkurtra (128k \/ 120s = 1092 lidhje \/ s).<\/li>\n<\/ul>\n<p><\/p>\n<p>Ka there jan\u00eb disa lloje aplikacionesh ni\u015fesh q\u00eb bien n\u00eb k\u00ebto kategori. P\u00ebr m\u00eb tep\u00ebr, n\u00ebse keni shum\u00eb armiq, mbushja e tabel\u00ebs conntrack t\u00eb serverit tuaj me shum\u00eb lidhje gjysm\u00eb t\u00eb hapura mund t\u00eb p\u00ebrdoret si nj\u00eb pjes\u00eb e nj\u00eb sulmi t\u00eb tipit \"refuzim sh\u00ebrbimi\" (DoS). N\u00eb t\u00eb dy rastet, conntrack mund t\u00eb b\u00ebhet nj\u00eb ngushtic\u00eb kufizuese n\u00eb sistemin tuaj. N\u00eb disa raste, rregullimi i parametrave t\u00eb tabel\u00ebs conntrack mund t\u00eb jet\u00eb i mjaftuesh\u00ebm p\u00ebr t\u00eb p\u00ebrmbushur nevojat tuaja \u2014 duke rritur madh\u00ebsin\u00eb ose duke reduktuar koh\u00ebt e pritjes conntrack (por n\u00ebse e b\u00ebni k\u00ebt\u00eb gabim, do t\u00eb p\u00ebrballeni me v\u00ebshtir\u00ebsi t\u00eb m\u00ebdha). P\u00ebr raste t\u00eb tjera, do t\u00eb nevojitet t\u00eb anashkaloni conntrack p\u00ebr trafikun agresiv.<\/p>\n<p><\/p>\n<h4 id=\"realnyy-primer\">Shembulli real<\/h4>\n<p><\/p>\n<p>Merrni nj\u00eb shembull konkret: nj\u00eb ofrues i madh SaaS me t\u00eb cilin kemi punuar kishte nj\u00eb s\u00ebr\u00eb serverash memcached n\u00eb hoste (jo n\u00eb makina\u865a), secili prej t\u00eb cil\u00ebve p\u00ebrballonte mbi 50,000 lidhje kalimtare n\u00eb sekond\u00eb.<\/p>\n<p><\/p>\n<p>Ata eksperimento p\u00ebr konfigurimin conntrack, rrit\u00ebn madh\u00ebsit\u00eb e tabelave dhe shkurtuan koh\u00ebn e gjurmimit, por konfigurimi ishte i pasigurt, duke rritur ndjesh\u00ebm konsumimin e RAM-it, q\u00eb ishte nj\u00eb problem (rreth GB)! Nd\u00ebrsa lidhjet ishin kaq t\u00eb shkurtra sa q\u00eb conntrack nuk krijonte p\u00ebrfitim t\u00eb zakonsh\u00ebm n\u00eb performanc\u00eb (ulje e konsumit t\u00eb CPU ose vonesave t\u00eb paketeve).<\/p>\n<p><\/p>\n<p>Si alternativ\u00eb, ata iu drejtuan Calico. Politikat e rrjetit t\u00eb Calico lejojn\u00eb q\u00eb t\u00eb mos p\u00ebrdoret conntrack p\u00ebr nj\u00eb lloj t\u00eb caktuar trafiku (duke p\u00ebrdorur p\u00ebr politik\u00ebn opsionin doNotTrack). Kjo u siguroi atyre nivelin e nevojsh\u00ebm t\u00eb performanc\u00ebs plus nj\u00eb nivel t\u00eb shtuar sigurie, q\u00eb ofrohet nga Calico.<\/p>\n<p><\/p>\n<h4 id=\"na-chto-pridetsya-poyti-chtoby-oboyti-conntrack\">\u00c7far\u00eb do t\u00eb b\u00ebhet p\u00ebr t\u00eb shmangur conntrack?<\/h4>\n<p><\/p>\n<ul>\n<li>Politikat e rrjetit do-not-track zakonisht duhet t\u00eb jen\u00eb simetrike. N\u00eb rastin e ofruesit SaaS: aplikacionet e tyre punonin brenda nj\u00eb zone t\u00eb mbrojtur dhe, p\u00ebrmes politik\u00ebs s\u00eb rrjetit, ata mund t\u00eb shtonin n\u00eb list\u00ebn e bardh\u00eb trafikun nga aplikacione specifike t\u00eb tjera, t\u00eb cilave u jepej leja p\u00ebr t\u00eb aksesuar memcached.<\/li>\n<li>Politika do-not-track nuk merr parasysh drejtimin e lidhjes. K\u00ebshtu, n\u00eb rastin e nj\u00eb sulmi ndaj serverit memcached, teorikisht \u00ebsht\u00eb e mundur t\u00eb p\u00ebrpiqeni t\u00eb lidhni \u00e7do klient memcached, n\u00ebse ai p\u00ebrdor portin e sakt\u00eb t\u00eb origjin\u00ebs. Megjithat\u00eb, n\u00ebse keni p\u00ebrcaktuar n\u00eb m\u00ebnyr\u00eb korrekte politik\u00ebn e rrjetit p\u00ebr klient\u00ebt tuaj memcached, k\u00ebto p\u00ebrpjekje p\u00ebr lidhje gjithsesi do t\u00eb refuzohen nga ana e klientit.<\/li>\n<li>Politika do-not-track zbatohet p\u00ebr \u00e7do paket\u00eb, ndryshe nga politikat e zakonshme, t\u00eb cilat zbatohet vet\u00ebm p\u00ebr paket\u00ebn e par\u00eb nga rrjedha. Kjo mund t\u00eb rris\u00eb konsumimin e burimeve CPU p\u00ebr nj\u00eb paket\u00eb, sepse p\u00ebr \u00e7do paket\u00eb nevojitet t\u00eb zbatohet politika. Por p\u00ebr lidhjet e shkurtra, ky konsum balan\u00e7ohet nga ulja e burimeve p\u00ebr p\u00ebrpunimin e conntrack. P\u00ebr shembull, n\u00eb rastin e nj\u00eb ofruesi SaaS, numri i paketave p\u00ebr \u00e7do lidhje ishte shum\u00eb i vog\u00ebl, prandaj shpenzimi shtes\u00eb i burimeve CPU p\u00ebr zbatimin e politikave p\u00ebr \u00e7do paket\u00eb ishte i justifikuar.<\/li>\n<\/ul>\n<p><\/p>\n<h4 id=\"pristupim-k-testam\">Le t\u00eb fillojm\u00eb testet.<\/h4>\n<p><\/p>\n<p>Ne kemi kryer nj\u00eb test n\u00eb nj\u00eb pod me serverin memcached dhe shum\u00eb pod me klient\u00ebt memcached, t\u00eb nisur n\u00eb nodat e larg\u00ebta, n\u00eb m\u00ebnyr\u00eb q\u00eb t\u00eb mund t\u00eb lan\u00e7ohej nj\u00eb num\u00ebr shum\u00eb i madh lidhjesh n\u00eb sekond\u00eb. Serveri me podin e serverit memcached kishte 8 b\u00ebrtham\u00eb dhe 512k regjistrime n\u00eb tabel\u00ebn conntrack (madh\u00ebsia e tabel\u00ebs e konfigurimit standard p\u00ebr hostin).<br \/>\nNe mat\u00ebm ndryshimin n\u00eb performanc\u00eb midis: pa politik\u00ebn rrjetore; me politik\u00ebn standarde Calico; dhe politik\u00ebn Calico do-not-track.<\/p>\n<p><\/p>\n<p>P\u00ebr testin e par\u00eb, ne caktuam numrin e lidhjeve n\u00eb 4.000 n\u00eb sekond\u00eb, k\u00ebshtu q\u00eb mund\u00ebm t\u00eb fokusohemi n\u00eb ndryshimin e konsumit t\u00eb CPU. Nuk kishte dallime t\u00eb r\u00ebnd\u00ebsishme midis munges\u00ebs s\u00eb politik\u00ebs dhe politik\u00ebs standarde, por do-not-track rriti konsumimin e CPU p\u00ebraf\u00ebrsisht me 20%:<\/p>\n<p>\n<img decoding=\"async\" alt=\"Kur Linux conntrack nuk \u00ebsht\u00eb m\u00eb nj\u00eb mik p\u00ebr ju\" src=\"\/wp-content\/uploads\/2020\/03\/6762772cb8e5f089a3ed444aff8cb8f4.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>N\u00eb testin e dyt\u00eb, ne aktivizuam sa m\u00eb shum\u00eb lidhje q\u00eb mund\u00ebm t\u00eb gjeneronim klient\u00ebt tan\u00eb dhe mat\u00ebm numrin maksimal t\u00eb lidhjeve n\u00eb sekond\u00eb q\u00eb mund t\u00eb trajtonte serveri yn\u00eb memcached. Si\u00e7 pritej, n\u00eb rastin e \"pa politika\" dhe \"politika e zakonshme\", t\u00eb dy arrit\u00ebn limitin conntrack t\u00eb mbi 4,000 lidhjeve n\u00eb sekond\u00eb (512k \/ 120s = 4,369 lidhje\/s). Me politik\u00ebn do-not-track, klient\u00ebt tan\u00eb d\u00ebrguan 60,000 lidhje n\u00eb sekond\u00eb pa asnj\u00eb problem. Jemi t\u00eb sigurt se mund t\u00eb rritnim k\u00ebt\u00eb num\u00ebr duke lidhur m\u00eb shum\u00eb klient\u00eb, por ndjejm\u00eb se k\u00ebto numra jan\u00eb mjaftuesh\u00ebm p\u00ebr t\u00eb ilustruar mesazhin e k\u00ebtij artikulli!<\/p>\n<p>\n<img decoding=\"async\" alt=\"Kur Linux conntrack nuk \u00ebsht\u00eb m\u00eb nj\u00eb mik p\u00ebr ju\" src=\"\/wp-content\/uploads\/2020\/03\/f3beeb1793a3158018274079da953a2c.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h4 id=\"zaklyuchenie\">P\u00ebrfundimi<\/h4>\n<p><\/p>\n<p>Conntrack \u00ebsht\u00eb nj\u00eb funksion i r\u00ebnd\u00ebsish\u00ebm i b\u00ebrtham\u00ebs. Ai kryen detyr\u00ebn e tij shum\u00eb mir\u00eb. P\u00ebrdoret shpesh nga komponent\u00ebt ky\u00e7 t\u00eb sistemit. Megjithat\u00eb, n\u00eb disa skenar\u00eb t\u00eb caktuar, ngarkesa p\u00ebr shkak t\u00eb conntrack tejkalon p\u00ebrfitimet e zakonshme q\u00eb ai ofron. N\u00eb k\u00ebt\u00eb skenar, politikat rrjetore Calico mund t\u00eb p\u00ebrdoren p\u00ebr t\u00eb \u00e7aktivizuar selektivisht p\u00ebrdorimin e conntrack q\u00eb ndihmon n\u00eb rritjen e nivelit t\u00eb siguris\u00eb rrjetore. P\u00ebr t\u00eb gjith\u00eb trafikun tjet\u00ebr, conntrack vazhdon t\u00eb mbetet shoku juaj!<\/p>\n<p><\/p>\n<h2 id=\"takzhe-chitayte-drugie-stati-v-nashem-bloge\">Shihni gjithashtu artikuj t\u00eb tjer\u00eb n\u00eb blogun ton\u00eb:<\/h2>\n<p><\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/nixys\/blog\/473578\/\">Montimi i moduleve dinamik\u00eb p\u00ebr Nginx<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/nixys\/blog\/473014\/\">Hyrje n\u00eb Autorizimin e Hashicorp Consul\u2019s Kubernetes<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/nixys\/blog\/426543\/\">Kopje rezerv\u00eb Stateful n\u00eb Kubernetes<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/nixys\/blog\/424717\/\">Kopjimi i nj\u00eb numri t\u00eb madh projektesh web t\u00eb ndryshme<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/nixys\/blog\/347526\/\">Boti Telegram p\u00ebr Redmine. Si ta thjeshtoni jet\u00ebn tuaj dhe t\u00eb tjer\u00ebve<\/a><\/noindex><\/li>\n<\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/nixys\/blog\/492686\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u043d\u0438\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439 (\u201cconntrack\u201d) \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0435\u0439 \u0441\u0435\u0442\u0435\u0432\u043e\u0433\u043e \u0441\u0442\u0435\u043a\u0430 \u044f\u0434\u0440\u0430 Linux. \u041e\u043d\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u044f\u0434\u0440\u0443 \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u0442\u044c \u0432\u0441\u0435 \u043b\u043e\u0433\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0441\u0435\u0442\u0435\u0432\u044b\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f \u0438\u043b\u0438 \u043f\u043e\u0442\u043e\u043a\u0438 \u0438 \u0442\u0435\u043c \u0441\u0430\u043c\u044b\u043c \u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0432\u0441\u0435 \u043f\u0430\u043a\u0435\u0442\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0442 \u043a\u0430\u0436\u0434\u044b\u0439 \u043f\u043e\u0442\u043e\u043a, \u0447\u0442\u043e\u0431\u044b \u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0431\u044b\u043b\u043e \u043f\u043e\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u043d\u043e \u043e\u0431\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0442\u044c \u0432\u043c\u0435\u0441\u0442\u0435. Conntrack \u2014 \u044d\u0442\u043e \u0432\u0430\u0436\u043d\u0430\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u044f\u0434\u0440\u0430, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0441\u043d\u043e\u0432\u043d\u044b\u0445 \u0441\u043b\u0443\u0447\u0430\u044f\u0445: NAT \u043e\u043f\u0438\u0440\u0430\u0435\u0442\u0441\u044f \u043d\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e\u0442 \u0441onntrack, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":74656,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-74655","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u043d\u0438\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439 (\u201cconntrack\u201d) \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kogda-linux-conntrack-vam-bolshe-ne-tovarishh\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u043e\u0433\u0434\u0430 Linux conntrack \u0432\u0430\u043c \u0431\u043e\u043b\u044c\u0448\u0435 \u043d\u0435 \u0442\u043e\u0432\u0430\u0440\u0438\u0449 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u043d\u0438\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439 (\u201cconntrack\u201d) \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kogda-linux-conntrack-vam-bolshe-ne-tovarishh\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-03-19T05:42:34+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-19T05:42:34+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Kur Linux conntrack nuk \u00ebsht\u00eb m\u00eb shoku juaj | ProHoster","description":"Monitorimi i lidhjeve (\u201cconntrack\u201d) \u00ebsht\u00eb.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kogda-linux-conntrack-vam-bolshe-ne-tovarishh","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u043e\u0433\u0434\u0430 Linux conntrack \u0432\u0430\u043c \u0431\u043e\u043b\u044c\u0448\u0435 \u043d\u0435 \u0442\u043e\u0432\u0430\u0440\u0438\u0449 | ProHoster","og:description":"\u041e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u043d\u0438\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0439 (\u201cconntrack\u201d) \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kogda-linux-conntrack-vam-bolshe-ne-tovarishh","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-03-19T05:42:34+00:00","article:modified_time":"2020-03-19T05:42:34+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"74655","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 18:10:25","updated":"2022-10-05 19:52:30","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/74655","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=74655"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/74655\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/74656"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=74655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=74655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=74655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}