[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
ipf states overload ?
Hello,
After I've redesigned my firewall to use keep-state and keep-frags
feature, I'm experiencing wierd behaviour of my OpenBSD (still 2.6)
box. After some days of continous work as a router and firewall, TCP connections
from machines behind this router/firewall goes very long to set up or
even don't set up at all.
I've found only one primitive solution for this - resetting ipf states, by ipf
-FS, or by ipf -D ; ipf -f /etc/ipf.rules -E
- immediately after that all TCP starts to work fine for the next 2-3 days.
The machine isn't very strong - intel 166, 40MB RAM - but load
averages never exceed 2% and there's still free memory and unused
swap. Anyway this looks like some kind of ipf overload.
--
Wojtuś.net
FidoNet: 2:484/47