From owner-freebsd-net@FreeBSD.ORG Thu Mar 26 12:52:23 2009 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 834B8106566B for ; Thu, 26 Mar 2009 12:52:23 +0000 (UTC) (envelope-from ady@ady.ro) Received: from mail-ew0-f171.google.com (mail-ew0-f171.google.com [209.85.219.171]) by mx1.freebsd.org (Postfix) with ESMTP id 1AA5D8FC18 for ; Thu, 26 Mar 2009 12:52:22 +0000 (UTC) (envelope-from ady@ady.ro) Received: by ewy19 with SMTP id 19so512839ewy.43 for ; Thu, 26 Mar 2009 05:52:22 -0700 (PDT) MIME-Version: 1.0 Received: by 10.210.35.17 with SMTP id i17mr619789ebi.77.1238071941923; Thu, 26 Mar 2009 05:52:21 -0700 (PDT) In-Reply-To: <1865.206.108.16.89.1238019698.squirrel@alder.hosix.com> References: <3650.206.108.16.89.1235691792.squirrel@alder.hosix.com> <3853.206.108.16.89.1235693214.squirrel@alder.hosix.com> <78cb3d3f0902261619t71a054fet43779c37e2981603@mail.gmail.com> <200902262341.35069.shawn@tandac.com> <49CAB28A.9030406@userid.org> <1865.206.108.16.89.1238019698.squirrel@alder.hosix.com> Date: Thu, 26 Mar 2009 13:52:21 +0100 Message-ID: <78cb3d3f0903260552g372fd4b6k886bba1ebc05a77c@mail.gmail.com> From: Adrian Penisoara To: Shawn Everett Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: freebsd-net@freebsd.org, Pierre Lamy Subject: Re: FreeBSD Router Problem X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 26 Mar 2009 12:52:23 -0000 Hi, On Wed, Mar 25, 2009 at 11:21 PM, Shawn Everett wrote: > > tcp.established 86400s > > > > ^^ This should be 3600. > > > > Pierre > > That's an interesting thought. Why would that matter? It's the PF TCP established session timeout, which defaults to 1 day. This is relevant only if you see a lot of ESTABLISHED sessions in the 'pfctl -s state' output, which appears not to be the case... Regards, Adrian.