Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 04 Apr 2009 11:44:31 +0200
From:      Sebastiaan van Erk <sebster@sebster.com>
To:        Artis Caune <artis.caune@gmail.com>
Cc:        freebsd-pf@freebsd.org
Subject:   Re: state mismatch/connection issues
Message-ID:  <49D72BFF.40109@sebster.com>
In-Reply-To: <9e20d71e0904021328u5e871322k1523c2ce0bf9fdd1@mail.gmail.com>
References:  <49C9F27F.3010505@sebster.com> <9e20d71e0904021328u5e871322k1523c2ce0bf9fdd1@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Hi,

Thanks for the reply.

> try without "block out log quick on $ext_if from !$ext_ip1 to any" rule.
I have other firewalls with the same rule which don't show the problem.

> btw, is your firewall forwarding traffic or doing nat?
Actually it does neither, there is no need for the backend servers to 
access the internet directly.

> Can you show pfctl -sr and ifconfig output?

Looking again at the pfctl -s info output, I saw something which I 
missed the first time around:

State Table                          Total             Rate
   current entries                      668
   searches                        70482052          118.5/s
   inserts                          8153087           13.7/s
   removals                         8152419           13.7/s
Counters
   match                           10637818           17.9/s
   bad-offset                             0            0.0/s
   fragment                               0            0.0/s
   short                                  0            0.0/s
   normalize                              1            0.0/s
   memory                           2405587            4.0/s
   bad-timestamp                          0            0.0/s
   congestion                             0            0.0/s
   ip-option                              0            0.0/s
   proto-cksum                          510            0.0/s
   state-mismatch                   2276240            3.8/s
   state-insert                           0            0.0/s
   state-limit                            0            0.0/s
   src-limit                              0            0.0/s
   synproxy                               0            0.0/s

The memory limit is hit almost the same amount of time as the state 
mismatches. It seems that my limits were simply too low. I have 
increased the limits (states/frags) and will see if the problem is 
resolved now.

Regards,
Sebastiaan

[-- Attachment #2 --]
0	*H
010	+0	*H
	Q00lS|
6$1-~j0
	*H
0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0
080630135157Z
090630135157Z0h10Uvan Erk10U*
Sebastiaan10USebastiaan van Erk1"0 	*H
	sebster@sebster.com0"0
	*H
0
Va\bEnݚa<M8ʄ^tv>x73bohi2oqS_¶Bm^p*I	x"9pt!jar#)n)^?'z<).+Ѐ4igR'UP*\Ւ,?.;?fBܯTzM IDվCK*3Yŧ
mcaztxʐsq/00.0U0sebster@sebster.com0U00
	*H
KT4W6ӽq]
tS` %f1G:HbzJj$EjE'JV~-VbVnJZE/`@@04!+T:c	پf`$Z=1#|oG[OBRG00lS|
6$1-~j0
	*H
0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0
080630135157Z
090630135157Z0h10Uvan Erk10U*
Sebastiaan10USebastiaan van Erk1"0 	*H
	sebster@sebster.com0"0
	*H
0
Va\bEnݚa<M8ʄ^tv>x73bohi2oqS_¶Bm^p*I	x"9pt!jar#)n)^?'z<).+Ѐ4igR'UP*\Ւ,?.;?fBܯTzM IDվCK*3Yŧ
mcaztxʐsq/00.0U0sebster@sebster.com0U00
	*H
KT4W6ӽq]
tS` %f1G:HbzJj$EjE'JV~-VbVnJZE/`@@04!+T:c	پf`$Z=1#|oG[OBRG0?0
0
	*H
010	UZA10UWestern Cape10U	Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0)	*H
	personal-freemail@thawte.com0
030717000000Z
130716235959Z0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA00
	*H
0Ħ<UsUNʙZhup[v:aQP
0cZ,p+Z?qV˯<6$*+w=+>@dקe*TH<a@dr`00U00CU<0:08642http://crl.thawte.com/ThawtePersonalFreemailCA.crl0U0)U"0 010UPrivateLabel2-1380
	*H
HP.
fgCL!6-6/P p<ab:~t%Pb'qW%ݩ9 Oe_N4[5MwV!x!5$F]_eO1q0m0v0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CAS|
6$1-~j0	+0	*H
	1	*H
0	*H
	1
090404094431Z0#	*H
	1=E?VPGdʠ0_	*H
	1R0P0	`He0
*H
0*H
0
*H
@0+0
*H
(0	+71x0v0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CAS|
6$1-~j0*H
	1xv0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CAS|
6$1-~j0
	*H
J'"(uL9S2SB	ڙOf۱CGg߈@R?táAh~*?	EeclWN^ĭxW\ź7Iq"J]Ļj|"
6^)g">AGP/4?){U2ǘAҷ&Cwd0J<dG-t"\3L+@h2!ד+ȪgNU눽ɧ2\&bZ[

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?49D72BFF.40109>