From owner-freebsd-stable Wed Sep 5 8: 4:35 2001 Delivered-To: freebsd-stable@freebsd.org Received: from bluenugget.net (bsd.st [64.3.150.188]) by hub.freebsd.org (Postfix) with ESMTP id E781C37B403 for ; Wed, 5 Sep 2001 08:04:27 -0700 (PDT) Received: by bluenugget.net (Postfix, from userid 1000) id B173C13615; Wed, 5 Sep 2001 08:06:31 -0700 (PDT) Date: Wed, 5 Sep 2001 08:06:31 -0700 From: Jason DiCioccio To: "David W. Chapman Jr." Cc: Cy Schubert - ITSD Open Systems Group , Mike Tancsa , stable@FreeBSD.ORG Subject: Re: ipnat bug Message-ID: <20010905080631.A75031@bluenugget.net> References: <20010905084833.F45611@leviathan.inethouston.net> <200109051359.f85Dxrw14875@cwsys.cwsent.com> <20010905090355.I45611@leviathan.inethouston.net> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="2fHTh5uZTiUOsy+g" Content-Disposition: inline In-Reply-To: <20010905090355.I45611@leviathan.inethouston.net> User-Agent: Mutt/1.3.21i Sender: owner-freebsd-stable@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG --2fHTh5uZTiUOsy+g Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Sep 05, 2001 at 09:03:55AM -0500, David W. Chapman Jr. wrote: > On Wed, Sep 05, 2001 at 06:59:16AM -0700, Cy Schubert - ITSD Open Systems= Group wrote: > > In message <20010905084833.F45611@leviathan.inethouston.net>, "David W.= =20 > > Chapman > > Jr." writes: > > > I'm not sure what the stats say, because since you told me what to=20 > > > look for I have no been able to reproduce it. Sometimes it happens= =20 > > > whithin a day, sometimes a week or two. > >=20 > > You might want to try posting this on the IP Filter mailing list: =20 > > ipfilter@coombs.anu.edu.au. Darren Reed, author and maintainer of IP= =20 > > Filter, is quite active on that ilst. > >=20 > >=20 > Thanks, I plan on it once the bug shows it self again and I can=20 > provide the propper output showing so. >=20 > --=20 > David W. Chapman Jr. I was actually heading towards state table size issues by the way.. But it = does not actually look like that is the issue (since ipnat -CF would not fix thi= s). Worth a shot though I suppose.. When it happens again look in the ipfstat -= s for the 'Maximum' value, it shouldn't be above 0. Of course it's worth looking= at everything that others have suggested too. Unless you have no stateful rul= es ;) Good luck, let us know when it happens again :-) Cheers, -JD- --=20 Jason DiCioccio - geniusj@bsd.st - PGP Key @ http://bsd.st/~geniusj/pgpkey.= asc --2fHTh5uZTiUOsy+g Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: PGP 6.5.8 iQA/AwUBO5Y/c9NQlZYENnwIEQI4dACg9z0nZWIi8UPiUk0fYL6DHKpc4cIAmwZ6 XZXN8zCb8wA4FAhxDxczzYuJ =QhxO -----END PGP SIGNATURE----- --2fHTh5uZTiUOsy+g-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-stable" in the body of the message