From owner-freebsd-ipfw@FreeBSD.ORG Fri Sep 10 20:46:13 2004 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 2C2C616A4CE for ; Fri, 10 Sep 2004 20:46:13 +0000 (GMT) Received: from mailhost.wsf.at (server202.serveroffice.com [217.196.72.202]) by mx1.FreeBSD.org (Postfix) with ESMTP id 86D5243D1D for ; Fri, 10 Sep 2004 20:46:11 +0000 (GMT) (envelope-from tw@wsf.at) Received: from mailhost.wsf.at (root@localhost)i8AKgb9F074732 for ; Fri, 10 Sep 2004 22:42:37 +0200 (CEST) (envelope-from tw@wsf.at) Received: from mailhost.wsf.at (http.wsf.at [217.196.72.203]) i8AKgbdn074724; Fri, 10 Sep 2004 22:42:37 +0200 (CEST) (envelope-from tw@wsf.at) Date: Fri, 10 Sep 2004 20:42:37 -0000 To: Ben Bentsen , freebsd-ipfw@freebsd.org From: Thomas Wolf X-Mailer: twiggi 1.10.3 Message-ID: <20040910224237.e7tduotip7ccgk@.mailhost.wsf.at> MIME-Version: 1.0 Content-Disposition: inline Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Subject: Re: kernel: ipfw: install_state: Too many dynamic rules X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: tw@wsf.at List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 10 Sep 2004 20:46:13 -0000 Ben Bentsen schrieb: > Hello group, > > Can any shed a little light on the following error messages. I have > spent a great deal of time looking at what is running at about > 9:30am-9:45am and have found nothing that I can pin to these errors. No > cron jobs are running anywhere even close to the time. TCPdump does not > shed any light either. This machine has only one purpose to pass, count, > limit and deny packets to a network Only SSH and FTP services are > enabled on this machine. What conditions case this message maybe I am > looking in the wrong place. > > INET ---- This Machine --- Catalyst 2820 ------ 14 computer units > > Aug 7 09:41:34 7206 /kernel: ipfw: install_state: Too many dynamic rules > Aug 10 09:41:207206 /kernel: ipfw: install_state: Too many dynamic rules [error messages snipped] [lot of rules without keep-state snipped] > > ipfw -q add 200 check-state > > ipfw -q add 275 count all from any to any keep-state keep-state on a 'count' - rule?? Never seen before. What is the purpose of this rule, besides filling up your dynamic rule table? ;-) Thomas -- Thomas Wolf Wiener Software Fabrik Dubas u. Wolf GMBH 1050 Wien, Mittersteig 4