[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: OpenBSD 3.5 Freezing as a network bridge with PF



  Hi Dean.

On Tue, Aug 03, 2004 at 12:51:21PM -0700, Dean wrote:
> 	I've setup a packet filtering bridge with OpenBSD 3.5-stable on
> a PIII 700MHz with 256MB of RAM. It has two Intel EtherExpress Pro 100
> NICs and one RTL-8139 Nic. When I am not in "bypass" mode (pass in/out
> quick on fxp0), my firewall will lock up unexpectedly in one to two
> days.

  Maybe you are running out of states?
  
  Try to increase the number of states and to reduce timeouts.
  Something like:
  
set limit   { states 50000 }
set timeout { adaptive.start 5000 adaptive.end 55000 \
              tcp.first 60 tcp.closing 60 tcp.closed 30 \
              tcp.established 43200 }

  Best regards,

-- 
 __  /*-    Frank DENIS (Jedi/Sector One) <j at 42-Networks.Com>    -*\  __
 \ '/    <a href="http://www.PureFTPd.Org/";> Secure FTP Server </a>    \' /
  \/  <a href="http://www.Jedi.Claranet.Fr/";> Misc. free software </a>  \/