Date: Sat, 04 Apr 2009 11:44:31 +0200 From: Sebastiaan van Erk <sebster@sebster.com> To: Artis Caune <artis.caune@gmail.com> Cc: freebsd-pf@freebsd.org Subject: Re: state mismatch/connection issues Message-ID: <49D72BFF.40109@sebster.com> In-Reply-To: <9e20d71e0904021328u5e871322k1523c2ce0bf9fdd1@mail.gmail.com> References: <49C9F27F.3010505@sebster.com> <9e20d71e0904021328u5e871322k1523c2ce0bf9fdd1@mail.gmail.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] Hi, Thanks for the reply. > try without "block out log quick on $ext_if from !$ext_ip1 to any" rule. I have other firewalls with the same rule which don't show the problem. > btw, is your firewall forwarding traffic or doing nat? Actually it does neither, there is no need for the backend servers to access the internet directly. > Can you show pfctl -sr and ifconfig output? Looking again at the pfctl -s info output, I saw something which I missed the first time around: State Table Total Rate current entries 668 searches 70482052 118.5/s inserts 8153087 13.7/s removals 8152419 13.7/s Counters match 10637818 17.9/s bad-offset 0 0.0/s fragment 0 0.0/s short 0 0.0/s normalize 1 0.0/s memory 2405587 4.0/s bad-timestamp 0 0.0/s congestion 0 0.0/s ip-option 0 0.0/s proto-cksum 510 0.0/s state-mismatch 2276240 3.8/s state-insert 0 0.0/s state-limit 0 0.0/s src-limit 0 0.0/s synproxy 0 0.0/s The memory limit is hit almost the same amount of time as the state mismatches. It seems that my limits were simply too low. I have increased the limits (states/frags) and will see if the problem is resolved now. Regards, Sebastiaan [-- Attachment #2 --] 0 *H 010 + 0 *H Q00lS| 6$1-~j0 *H 0b10 UZA1%0#U Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0 080630135157Z 090630135157Z0h10Uvan Erk10U* Sebastiaan10USebastiaan van Erk1"0 *H sebster@sebster.com0"0 *H 0 Va\bEnݚa<M8ʄ^tv>x73bohi2oqS_¶Bm^p*I x"9pt!jar#)n)^?'z<).+Ѐ4igR'UP*\Ւ,?.;?fBܯTzM IDվCK*3Yŧ mcaztxʐsq/ 00.0U0sebster@sebster.com0U0 0 *H KT4W6ӽq] tS` %f1G:H b zJj$EjE'JV~-VbVnJZE/`@@04!+T:c پf`$Z=1#|oG[OBRG00lS| 6$1-~j0 *H 0b10 UZA1%0#U Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0 080630135157Z 090630135157Z0h10Uvan Erk10U* Sebastiaan10USebastiaan van Erk1"0 *H sebster@sebster.com0"0 *H 0 Va\bEnݚa<M8ʄ^tv>x73bohi2oqS_¶Bm^p*I x"9pt!jar#)n)^?'z<).+Ѐ4igR'UP*\Ւ,?.;?fBܯTzM IDվCK*3Yŧ mcaztxʐsq/ 00.0U0sebster@sebster.com0U0 0 *H KT4W6ӽq] tS` %f1G:H b zJj$EjE'JV~-VbVnJZE/`@@04!+T:c پf`$Z=1#|oG[OBRG0?0 0 *H 010 UZA10UWestern Cape10U Cape Town10U Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H personal-freemail@thawte.com0 030717000000Z 130716235959Z0b10 UZA1%0#U Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA00 *H 0 Ħ<UsUNʙZhup[v:aQP 0cZ,p+Z?qV˯<6$*+w=+>@dקe*TH<a@dr` 00U0 0CU<0:08642http://crl.thawte.com/ThawtePersonalFreemailCA.crl0U0)U"0 010UPrivateLabel2-1380 *H HP. fgCL!6-6/P p<ab:~ t%Pb'qW%ݩ9 Oe_N4[5MwV!x!5$F]_eO1q0m0v0b10 UZA1%0#U Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CAS| 6$1-~j0 + 0 *H 1 *H 0 *H 1 090404094431Z0# *H 1=E?VPGdʠ0_ *H 1R0P0 `He0 *H 0*H 0 *H @0+0 *H (0 +71x0v0b10 UZA1%0#U Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CAS| 6$1-~j0*H 1xv0b10 UZA1%0#U Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CAS| 6$1-~j0 *H J'"(uL9S2SB ڙOf۱CGg߈@R?táA h~*? EeclWN^ĭxW\ź7Iq"J]Ļj|" 6^)g">AGP/4?){U2ǘAҷ&Cwd0J<dG-t"\3L+@h2!ד+ȪgNU눽ɧ2\&bZ[
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?49D72BFF.40109>
