Share your knowledge at the LQ Wiki.
Go Back > Forums > Linux Forums > Linux - Security
User Name
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.


Closed Thread
  Search this Thread
Old 01-05-2005, 05:25 AM   #1
LQ Newbie
Registered: Jun 2004
Location: Zimbabwe
Distribution: redhat
Posts: 21

Rep: Reputation: 15
Neighbour table Overflow

I getting the following error message on the linux box

Neighbour Table Overflow

This is slowing down the network and most of the service are now not running
It seems once i remove the network cable for the the internal network this messages stops coming out and resurfaces once i plug it in

i am running Redhat 9
Old 01-10-2005, 11:29 PM   #2
Senior Member
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
You might have some luck increasing the garbage collection values in /proc/sys/net/ipv4/neigh/default/gc_thresh*

If there aren't more than 128 hosts on the LAN you're plugged into, then you likely have some kind of networking issue, like 2 machines with the same hostname or an infected machine spewing out false ARP entires. Either way, fire up tcpdump/ethereal and see if the traffic looks abnormal.
Old 02-24-2006, 04:03 PM   #3
LQ Newbie
Registered: May 2001
Posts: 4

Rep: Reputation: 0
I am running Debian Sarge with linux-2.6.8-2-386 on my router/firewall/proxy and have the same problem. I try changing values of /proc/sys/net/ipv4/neigh/default/gc_thresh* and droping udp 1434 as pe2338 said but "neighbour table overflow" message continue. Does any one have yet a working solution?
Old 02-24-2006, 06:17 PM   #4
Registered: Dec 2005
Distribution: CentOS 5 - Debian 5
Posts: 112

Rep: Reputation: 15
>>Neighbour Table Overflow

I hate to be your neighbour
Old 08-18-2010, 10:19 PM   #5
LQ Newbie
Registered: Aug 2009
Location: BHOPAL
Posts: 6

Rep: Reputation: 0
Neighbour Table Overflow Resolved

Neighbour Table Overflow occurs when there are two many ARP requests which the server is not able to reply. If u hv a huge flat network then the only solution is to increase the threshhold values in /etc/sysctl.conf

Add following lines to /etc/sysctl.conf (redhat)

net.ipv4.neigh.default.gc_thresh1 = 4096
net.ipv4.neigh.default.gc_thresh2 = 8192
net.ipv4.neigh.default.gc_thresh3 = 8192
net.ipv4.neigh.default.base_reachable_time = 86400
net.ipv4.neigh.default.gc_stale_time = 86400

and restart the machine

Last edited by asnani_satish; 08-18-2010 at 10:31 PM.
Old 08-19-2010, 12:44 AM   #6
LQ Guru
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
asnani_satish, please don't resurrect dead threads.

Check the dates before you post.

Closed Thread

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
neighbour table overflow hammadrs Linux - Software 4 02-24-2006 03:48 PM
"Neighbour table overflow." blocking internet Riddick Linux - Networking 5 11-17-2005 02:40 PM
Neighbour table overflow due to windows worm/spyware demian Linux - Security 3 10-06-2004 07:53 AM
kernel: Neighbour table overflow basbosco Linux - Software 0 06-19-2004 03:24 AM
net: 70 messages suppressed; neighbour table overflow is the message, only problem techguy2 Linux - Networking 0 10-03-2003 07:57 AM > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:44 PM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration