+sub update_nf_conntrack_max {
+ my ($hostfw_conf) = @_;
+
+ my $max = 65536; # reasonable default
+
+ my $options = $hostfw_conf->{options} || {};
+
+ if (defined($options->{nf_conntrack_max}) && ($options->{nf_conntrack_max} > $max)) {
+ $max = $options->{nf_conntrack_max};
+ $max = int(($max+ 8191)/8192)*8192; # round to multiples of 8192
+ }
+
+ my $filename_nf_conntrack_max = "/proc/sys/net/nf_conntrack_max";
+ my $filename_hashsize = "/sys/module/nf_conntrack/parameters/hashsize";
+
+ my $current = int(PVE::Tools::file_read_firstline($filename_nf_conntrack_max) || $max);
+
+ if ($current != $max) {
+ my $hashsize = int($max/4);
+ PVE::ProcFSTools::write_proc_entry($filename_hashsize, $hashsize);
+ PVE::ProcFSTools::write_proc_entry($filename_nf_conntrack_max, $max);
+ }
+}
+