Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 31 Jan 2002 21:40:14 -0800
From:      "Crist J. Clark" <cristjc@earthlink.net>
To:        Mario Doria <madd@tecdigital.net>
Cc:        freebsd-questions@FreeBSD.ORG
Subject:   Re: IPFW Keep-state ruleset sysctl values
Message-ID:  <20020131214014.K152@gohan.cjclark.org>
In-Reply-To: <009b01c1aad6$5f146560$0a00a8c0@Deathstar>; from madd@tecdigital.net on Thu, Jan 31, 2002 at 10:10:16PM -0600
References:  <009b01c1aad6$5f146560$0a00a8c0@Deathstar>

next in thread | previous in thread | raw e-mail | index | archive | help
On Thu, Jan 31, 2002 at 10:10:16PM -0600, Mario Doria wrote:
[snip]

> After changing IPF with IPFW, I noticed that connections timed out very
> quickly. I changed
> net.inet.ip.fw.dyn_ack_lifetime to 14400 and it got better. When using IPF,
> connections timed out at 86400 seconds (I think) which is way more thant
> 14400. I *think* the IPF timeout is the one specified for TCP/IP but I think
> 14400 (4 hours) is more realistical. Question is: Is this change going to
> affect me in other ways?

I don't think that there is such thing as a "specified" timeout for
firewalls. (And if there was firewalls by their very nature tend to be
broken with respect to certain requirements for hosts and routers.)

> Second doubt here, I also changed the sysctl value of net.inet.ip.fw.dyn_max
> to 3000. Is this too much or too little?.
> The machine is a midly loaded webserver, which also serves as a Samba server
> for 20 multimedia users (meaning they open a bazillion files at once). I
> don't know how many dynamic rules is the maximum for IPF, I thought 3000 was
> reasonable.

With vague statements like, "mildly loaded webserver," which could
mean a _very_ broad range, I don't think you can get much
help from the list. However, the best thing will probably just be to
see what value works for you. The firewall will log the problem if you
do bump into the rule limit, so you will know if it happens.
-- 
Crist J. Clark                     |     cjclark@alum.mit.edu
                                   |     cjclark@jhu.edu
http://people.freebsd.org/~cjc/    |     cjc@freebsd.org

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020131214014.K152>