From owner-freebsd-net@FreeBSD.ORG Sat Sep 11 13:24:13 2004 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 07ECC16A4CE for ; Sat, 11 Sep 2004 13:24:13 +0000 (GMT) Received: from xorpc.icir.org (xorpc.icir.org [192.150.187.68]) by mx1.FreeBSD.org (Postfix) with ESMTP id E261843D46 for ; Sat, 11 Sep 2004 13:24:12 +0000 (GMT) (envelope-from rizzo@icir.org) Received: from xorpc.icir.org (localhost [127.0.0.1]) by xorpc.icir.org (8.12.9p1/8.12.8) with ESMTP id i8BDO6Ib037614; Sat, 11 Sep 2004 06:24:06 -0700 (PDT) (envelope-from rizzo@xorpc.icir.org) Received: (from rizzo@localhost) by xorpc.icir.org (8.12.9p1/8.12.3/Submit) id i8BDO624037613; Sat, 11 Sep 2004 06:24:06 -0700 (PDT) (envelope-from rizzo) Date: Sat, 11 Sep 2004 06:24:06 -0700 From: Luigi Rizzo To: Don Bowman Message-ID: <20040911062406.A37565@xorpc.icir.org> References: Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5.1i In-Reply-To: ; from don@sandvine.com on Fri, Sep 10, 2004 at 03:51:48PM -0400 cc: freebsd-net@freebsd.org cc: Glenn Dawson Subject: Re: dyn buckets X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 11 Sep 2004 13:24:13 -0000 On Fri, Sep 10, 2004 at 03:51:48PM -0400, Don Bowman wrote: > From: owner-freebsd-net@freebsd.org > > I have a firewall running 4.10 that handles around > > 20mbits/sec of traffic > > and has around 500 ipfw rules. > > > > Lately I've noticed that net.inet.ip.fw.curr_dyn_buckets > > seems to be maxing > > out. I've increased net.inet.ip.fw.dyn_buckets a few times, what hits the limit is the number of rules not the number of buckets -- try raising net.inet.ip.fw.dyn_max as suggested. cheers luigi > > but they seem > > to max out each time. > > > > Is there any problem with increasing > > net.inet.ip.fw.dyn_buckets far beyond > > the default? (I'm at 2048 now) > > I use > net.inet.ip.fw.dyn_buckets=16384 > net.inet.ip.fw.dyn_syn_lifetime=5 > net.inet.ip.fw.dyn_max=32000 > > > _______________________________________________ > freebsd-net@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-net > To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"