Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 17 Aug 2011 15:31:44 +0200
From:      =?ISO-8859-1?Q?Ermal_Lu=E7i?= <eri@freebsd.org>
To:        Florian Smeets <flo@freebsd.org>
Cc:        "Bjoern A. Zeeb" <bzeeb-lists@lists.zabbadoz.net>, freebsd-pf@freebsd.org
Subject:   Re: svn commit: r223637 - in head: . contrib/pf/authpf contrib/pf/ftp-proxy contrib/pf/man contrib/pf/pfctl contrib/pf/pflogd sbin/pflogd sys/conf sys/contrib/altq/altq sys/contrib/pf/net sys/modules s...
Message-ID:  <CAPBZQG2kRYvzVsXdtdG54Jbu3oZF7NsW61kuqEboChX9tjEWrA@mail.gmail.com>
In-Reply-To: <4E4BBCB0.4090003@freebsd.org>
References:  <201106281157.p5SBvP5g048097@svn.freebsd.org> <EA6E6909-A42B-4CF2-891A-B8A80E2B8476@FreeBSD.org> <20110629192224.2283efc8@fabiankeil.de> <20110707193539.GA60591@dragon.NUXI.org> <CAPBZQG1ZOBJh0BMPH%2BkKAHfWJoYCubdGunncd5Bhd7y39-_fkA@mail.gmail.com> <20110708170240.GA59024@dragon.NUXI.org> <4E4BB39D.8070903@freebsd.org> <22DE2AEF-22A3-4B6E-9E24-DCF0EDF40933@lists.zabbadoz.net> <4E4BB602.2060205@freebsd.org> <CAPBZQG080N4xyDLG7y1rCprsa5oo7Dtshk1ny7j4-M3bEXhkaA@mail.gmail.com> <4E4BBCB0.4090003@freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, Aug 17, 2011 at 3:05 PM, Florian Smeets <flo@freebsd.org> wrote:
> On 17.08.2011 14:58, Ermal Lu=C3=A7i wrote:
>>
>> On Wed, Aug 17, 2011 at 2:37 PM, Florian Smeets<flo@freebsd.org> =C2=A0w=
rote:
>>>
>>> On 17.08.2011 14:30, Bjoern A. Zeeb wrote:
>>>>
>>>> On Aug 17, 2011, at 12:27 PM, Florian Smeets wrote:
>>>>
>>>>> On 08.07.2011 19:02, David O'Brien wrote:
>>>>>>
>>>>>> On Fri, Jul 08, 2011 at 02:26:37PM +0200, Ermal Lui wrote:
>>>>>>>
>>>>>>> On Thu, Jul 7, 2011 at 9:35 PM, David O'Brien<obrien@freebsd.org>
>>>>>>> wrote:
>>>>>>>>
>>>>>>>> I have 'pfctl', 'netstat', 'netstat -rn', and 'sysctl -a' output
>>>>>>>> from
>>>>>>>> one
>>>>>>>> of these experiences. =EF=BF=BDWould they be useful to you in look=
ing into
>>>>>>>> this?
>>>>>>>
>>>>>>> please send those.
>>>>>>> Also useful would be a description of your setup.
>>>>>>
>>>>>> Ermal,
>>>>>> Thanks. =C2=A0I'll send to you off list.
>>>>>>
>>>>>
>>>>> Hi,
>>>>>
>>>>> did you guys find out what was wrong? I may have a similar problem. M=
y
>>>>> server loses connection after some time. I think it is because the
>>>>> state
>>>>> table is getting full, but i only have a couple of active states.
>>>>>
>>>>> The current entries keep increasing, i had ~3600 this morning.
>>>>>
>>>>> flo@tb:~ # sudo pfctl -vsi|grep "current entries"
>>>>> No ALTQ support in kernel
>>>>> ALTQ related functions disabled
>>>>> =C2=A0current entries =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 4891
>>>>> =C2=A0current entries =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A00
>>>>> flo@tb:~ # sudo pfctl -ss| wc -l
>>>>> No ALTQ support in kernel
>>>>> ALTQ related functions disabled
>>>>> =C2=A0 =C2=A0 =C2=A012
>>>>>
>>>>> Every new connection is added to the current entries but it seems the=
y
>>>>> are never removed?!
>>>>>
>>>>> I've set debug to loud, what else should i do to track this down?
>>>>
>>>>
>>
>> There is a thread in freebsd-net@ explaining some culprits with
>> state table numbers from pfctl -ss =C2=A0and number from pfctl -vsi.
>>
>
> Ok, having another look at pfctl -vsi it looks like it confirms my suspic=
ion
> that states do not get removed.
>
> State Table =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Total =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 Rate
> =C2=A0current entries =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0 =C2=A0 =C2=A0 5082
> =C2=A0searches =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0296083 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0=
 =C2=A03.7/s
> =C2=A0inserts =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 5082 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A00.1/s
> =C2=A0removals =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A00.0/s
>
Well really it depends on the timeframe this statistic was taken!

I do not want to be a nonbeliver but this was confirmed working by
other people that reported the same 'issue'.

Other than that you can do a pfctl -dvvss and pfctl -dvvsi for every
minute and send them to compare.
Further more there should be a kernel thread "pfpurge" that is
running, verify with procstat which does the job of purging your
states.

--=20
Ermal



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAPBZQG2kRYvzVsXdtdG54Jbu3oZF7NsW61kuqEboChX9tjEWrA>