From owner-freebsd-questions@FreeBSD.ORG Mon Feb 7 06:16:41 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 915C616A4CE for ; Mon, 7 Feb 2005 06:16:41 +0000 (GMT) Received: from ms-smtp-04.rdc-kc.rr.com (ms-smtp-04.rdc-kc.rr.com [24.94.166.116]) by mx1.FreeBSD.org (Postfix) with ESMTP id 29E9943D49 for ; Mon, 7 Feb 2005 06:16:41 +0000 (GMT) (envelope-from bbayorgeon@new.rr.com) Received: from Marshal (CPE-67-48-29-178.new.rr.com [67.48.29.178]) j1765UxH022616 for ; Mon, 7 Feb 2005 00:05:47 -0600 (CST) From: "Brian" To: Date: Mon, 7 Feb 2005 00:16:44 -0600 Message-ID: <000201c50cdc$a0c28c10$4402000a@Marshal> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook, Build 10.0.4024 X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180 Importance: Normal X-Virus-Scanned: Symantec AntiVirus Scan Engine Subject: ipfw / drop sessions / incoming http / keep-state X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 07 Feb 2005 06:16:41 -0000 Greetings: I'm trying to sort out an issue with drop session error messages...see below Can some please explain what the difference / benefits between the two possible firewall rules shown below? I have been uncertain if I should use the keep-state option for the incoming connections. Incoming Connections seen to work ok without keep-state, But I also seem to get the drop session errors When there are incoming http connections Thanks for you help Brian >From firewall script #$cmd 396 allow tcp from any to me 80 in via $oif setup limit src-addr 4 # Incoming http connections $cmd 396 allow tcp from any to me 80 in via $oif setup $ks # Incoming http connections >From Log File Feb 6 12:03:25 rakort kernel: drop session, too many entries Feb 6 12:03:51 rakort last message repeated 4 times Feb 6 12:05:46 rakort last message repeated 13 times