Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 10 Sep 2004 20:42:37 -0000
From:      Thomas Wolf <tw@wsf.at>
To:        Ben Bentsen <freebsd@usww.com>, freebsd-ipfw@freebsd.org
Subject:   Re: kernel: ipfw: install_state: Too many dynamic rules
Message-ID:  <20040910224237.e7tduotip7ccgk@.mailhost.wsf.at>

next in thread | raw e-mail | index | archive | help

Ben Bentsen <freebsd@usww.com> schrieb:

> Hello group,
> 
> Can any shed a little light on the following error messages. I have 
> spent a great deal of time looking at what is running at about 
> 9:30am-9:45am and have found nothing that I can pin to these errors. No 
> cron jobs are running anywhere even close to the time. TCPdump does not 
> shed any light either. This machine has only one purpose to pass, count, 
> limit and deny packets to a network Only SSH and FTP services are 
> enabled on this machine. What conditions case this message maybe I am 
> looking in the wrong place.
> 
> INET ----  This Machine ---  Catalyst 2820 ------ 14 computer units
> 
> Aug  7 09:41:34 7206 /kernel: ipfw: install_state: Too many dynamic rules
> Aug 10 09:41:207206 /kernel: ipfw: install_state: Too many dynamic rules
[error messages snipped]
[lot of rules without keep-state snipped]
> 
> ipfw -q add 200 check-state
> 
> ipfw -q add 275 count all from any to any keep-state

keep-state on a 'count' - rule??
Never seen before. What is the purpose of this rule,
besides filling up your dynamic rule table? ;-)

Thomas

--
Thomas Wolf
Wiener Software Fabrik
Dubas u. Wolf GMBH
1050 Wien, Mittersteig 4



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040910224237.e7tduotip7ccgk>