SingaporeRep
Member
Benchmark Addict
- Joined:
- Jul 2024
- Posts:
- 227
- From:
- Singapore, SG
CPU dropped to 12% at same throughput
That is a hell of a drop. 85 to 12 means conntrack was eating 73 percentage points of CPU doing basically nothing useful for WireGuard.
I retested on my end with hashsize bumped to 65536. 147 Mbps -> 312 Mbps, CPU 61%. Better but not clean. Raw table rule took me to 940 Mbps line rate, CPU 18%.
Conntrack is a tax.
fio, iperf, geekbench. results or gtfo.
YuriDavid
Member
- Joined:
- May 2024
- Posts:
- 174
- From:
- Kyiv, Ukraine
It is worse than a tax. It is a tax with quadratic growth.
I plotted nf_conntrack_count against peer count on my setup. Linear to about 80 peers, then knee at 120, then cliff. The hash collision path is real.
The fix it is simple! You go into config of kernel and you make the table big!
Bigger table defers problem. Does not solve. With 200 peers I would need 1M entries, that is 256MB RAM just for conntrack, on a 2GB VPS.
Raw table or dedicated conntrack bypass module are only sane paths at scale.
indentation is not optional
ronwit
Member
Budget King
- Joined:
- Jun 2024
- Posts:
- 122
- From:
- Osaka, Japan
The RAM it eats! I forget to say! My server it is only 1GB and I use 180MB for conntrack after the fix! This is big!
Before the fix the server it die. After the fix the server it live but hungry (´・ω・`)
I think for malý server the raw table is best. No memory, no problem.
instant noodles, instant deploys
Hana5
Member
GPU poor
- Joined:
- Jun 2024
- Posts:
- 104
- From:
- Tokyo, Japan
Same here. I had the same conntrack stall on a 2-core Tokyo Vultr, 1GB RAM. Not WireGuard, OpenVPN, but same kernel path. Nf_conntrack_max at default, hit wall at ~25 clients.
I did not fix with bigger table. I moved to Hetzner Singapore, same specs, half price, fresh install. Problem identical. It is not provider. It is Linux.
Now I use the raw table rule. 3 months, zero stalls.
8-char NTLM found in 4min 32sec
hankels
Member
52 VPS and counting
- Joined:
- Jun 2024
- Posts:
- 301
- From:
- Phoenix, US
Moved to Hetzner Singapore
Closest I can get from Tokyo.
But the point stands. This is kernel behavior, not provider.
For anyone keeping score, my 52 VPS spreadsheet says:
- Vultr: conntrack hashsize 1024 default, can resize live
- Hetzner: 4096 default, resize needs reboot
- GreenCloudVPS Singapore: 8192 default, but their kernel is custom, maybe patched
- RackNerd: 1024 default, old 5.4 kernels on some nodes, resize broken
The raw table rule is portable. The module param is not.
seedbox, NAS, tape, and three offsite