Re: bridge tagging limits?

2004-05-28 Thread Can Erkin Acar
On Thu, May 27, 2004 at 04:56:41PM -0400, Jim Zajkowski wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Hi all, > > Does anyone have any experience with the number of rules a bridge can > handle? We're thinking about how our wireless network policy, and we'd > like to filter by MA

pf firewall loses connectivity at 50,000 state table entries (patch to correct this?)

2004-05-28 Thread Sean
Hi all, Seems our 3.5 firewall becomes totally unresponsive at around 50,000 state table entries, despite a 200,00 state table limit. As soon as I clear the state table, the firewall immediately recovers. I've been told there is a patch or series of patches that can remedy this behavior. Are they

Re: pf firewall loses connectivity at 50,000 state table entries (patchto correct this?)

2004-05-28 Thread Nick Holland
Nick Holland wrote: .. > You don't like the (good) answers you got on [EMAIL PROTECTED] my appologies, that was uncalled for. the fact that *I* didn't read any pf list messages this yet this morning doesn't mean they have just arrived. *sigh* Nick. -- http://www.holland-consulting.net

Re: pf firewall loses connectivity at 50,000 state table entries (patch to correct this?)

2004-05-28 Thread Tyson E Lefebvre
Sean wrote: Hi all, Seems our 3.5 firewall becomes totally unresponsive at around 50,000 state table entries, despite a 200,00 state table limit. As soon as I clear the state table, the firewall immediately recovers. I've been told there is a patch or series of patches that can remedy this behavior

Re: pf firewall loses connectivity at 50,000 state table entries (patchto correct this?)

2004-05-28 Thread Nick Holland
Sean wrote: > > Hi all, > > Seems our 3.5 firewall becomes totally unresponsive at around 50,000 > state table entries, despite a 200,00 state table limit. As soon as I > clear the state table, the firewall immediately recovers. I've been told > there is a patch or series of patches that can reme

Re: pf firewall loses connectivity at 50,000 state table entries (patch to correct this?)

2004-05-28 Thread Mike Frantzen
> Seems our 3.5 firewall becomes totally unresponsive at around 50,000 > state table entries, despite a 200,00 state table limit. As soon as I > clear the state table, the firewall immediately recovers. I've been told > there is a patch or series of patches that can remedy this behavior. Are > they

Re: pf firewall loses connectivity at 50,000 state table entries (patch to correct this?)

2004-05-28 Thread Sean
Tyson E Lefebvre wrote: >> > You already posted this misc@ and they told you what to do. You're > setting NMBCLUSTERS and you shouldn't. Follow the advice of misc@ and > you will be fine. > Those responses came after I posted here. Thanks for the reply, though. Sean