Making progress on pf tuning

2007-10-25 Thread Russell Fulton
I have been in touch with Willem and should have the congestion counters added to symon today or at worst over the weekend (it being Friday afternoon here). Any other pf counters people want while I'm about it? I have raised the net.inet.ip.ifq.maxlen to 1024 (the box has 4 active interfaces).

PF Timeout and optimization warning

2007-10-25 Thread rmkml
Hi, just warn if you use Timeout and optimization on PF, ok first example on pf.conf : set timeout tcp.established 86399 #set optimization normal#Without set optimization * !!! and pfctl -s timeout|grep established tcp.established 86399s ok second example and Warning on pf.conf : s

Re: linux/iptables/proxy arp to pf/redundant firewall

2007-10-25 Thread Russell Fulton
Henning Brauer wrote: > so get a little transfer net and make your upstream adjust his routes > > otherwise you need a bridge indeed, but you really want to avoid that > if you have a chance to go for regular routed with carp etc. > > we also run redundant bridges -- we have two physical pat

Re: Still dealing with pf performance issues

2007-10-25 Thread Jon Hart
As you and others have stated, the 4.2 upgrade will probably help. What does 'pfctl -vsi' say? Anything different? If I were in your shoes, I'd do exactly what you are doing -- the 4.2 upgrade and search for NICs with better interrupt handling. In a previous life when I was doing a lot more pf