Re: pf state disappearing [ adaptive timeout bug ]

2016-01-22 Thread Nick Rogers
On Thu, Jan 21, 2016 at 11:44 AM, Matthew Grooms wrote: > On 1/21/2016 11:04 AM, Nick Rogers wrote: > >> On Wed, Jan 20, 2016 at 2:01 PM, Matthew Grooms >> wrote: >> >> All, >>> >>> I have a curious problem with a lightly loaded pair of pf firewall >>>

Re: pf state disappearing [ adaptive timeout bug ]

2016-01-22 Thread Matthew Grooms
On 1/22/2016 3:35 PM, Nick Rogers wrote: On Thu, Jan 21, 2016 at 11:44 AM, Matthew Grooms wrote: # pfctl -si Status: Enabled for 0 days 02:25:41 Debug: Urgent State Table Total Rate current entries77759

Re: pf state disappearing [ adaptive timeout bug ]

2016-01-21 Thread Matthew Grooms
On 1/21/2016 11:04 AM, Nick Rogers wrote: On Wed, Jan 20, 2016 at 2:01 PM, Matthew Grooms wrote: All, I have a curious problem with a lightly loaded pair of pf firewall running on FreeBSD 10.2-RELEASE. I'm noticing TCP entries are disappearing from the state table for no

pf state disappearing

2016-01-20 Thread Matthew Grooms
All, I have a curious problem with a lightly loaded pair of pf firewall running on FreeBSD 10.2-RELEASE. I'm noticing TCP entries are disappearing from the state table for no good reason that I can see. The entry limit is set to 10 and I never see the system go over about 7 entries,