[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
problem with keep state limit
Hello,
I have version OpenBSD xxx 2.7 compile#0 i386, with ipf -V
ipf: IP Filter: v3.3.16 (184)
Kernel: IP Filter: v3.3.16
I have about 5 systems behind firewall and I use 4 ipf rules with keep state
like
pass in quick on xxxx proto tcp from any to IP flags S/SA keep state
The fifth server is very loaded (100 incoming TCP sessions per second -
email server) and when I changed rule to also use keep state, openBSD
started send ICMP host IP unreachable to the Internet users, passing only
some traffic (like shaping). ipfstat -s shows that there are abou 2000
concurent TCP sessions. Is too much?
I had to change ipf.rules to explicitly allow incoming and outgoing packets
on each interface (so not to use keep state).
Does anobody have any solution?
Thank you.
Vladimír Jirásek
IT Security Administration, C731
RadioMobil, a.s.
+420603402718