From owner-freebsd-pf@FreeBSD.ORG Thu Jan 19 16:32:38 2012 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 98FF21065670 for ; Thu, 19 Jan 2012 16:32:38 +0000 (UTC) (envelope-from wooh@wooh.hu) Received: from mail.bsdsupportservice.hu (mail.bsdsupportservice.hu [194.38.104.120]) by mx1.freebsd.org (Postfix) with ESMTP id 51D538FC15 for ; Thu, 19 Jan 2012 16:32:37 +0000 (UTC) Received: from kazoku (localhost [127.0.0.1]) by mail.bsdsupportservice.hu (Postfix) with ESMTP id A8A1B73381; Thu, 19 Jan 2012 17:30:57 +0100 (CET) X-Virus-Scanned: amavisd-new at bsdsupportservice.hu Received: from mail.bsdsupportservice.hu ([127.0.0.1]) by kazoku (mail.bsdsupportservice.hu [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dbeJTsioxOGX; Thu, 19 Jan 2012 17:30:52 +0100 (CET) Received: from helium-2.local (catv-89-135-87-165.catv.broadband.hu [89.135.87.165]) by mail.bsdsupportservice.hu (Postfix) with ESMTPA id 6D2E3731AB; Thu, 19 Jan 2012 17:30:52 +0100 (CET) Message-ID: <4F18459D.6060000@wooh.hu> Date: Thu, 19 Jan 2012 17:32:29 +0100 From: Adam PAPAI User-Agent: Postbox 3.0.2 (Macintosh/20111203) MIME-Version: 1.0 To: "Bartek W. aka Mastier" References: <4F183944.30101@wooh.hu> <4F183E6F.2030709@gmail.com> In-Reply-To: <4F183E6F.2030709@gmail.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Cc: freebsd-pf@freebsd.org Subject: Re: Maximum throughput ? limit? X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 19 Jan 2012 16:32:38 -0000 Bartek W. aka Mastier wrote: >> > Indeed. The default maximum is 10 000 states as I remember. > > I.e. one of the main routers in my case. core quad. > > set limit { states 300000, frags 10000, src-nodes 100000 } I had the states up to 250000 but the frags and scr-nodes were the default. What's your timeout interval? -- Adam PAPAI http://www.wooh.hu E-mail: wooh@wooh.hu Phone: +36 30 33-55-735 (Hungary)