Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 29 Apr 2003 15:43:47 +0200
From:      Antoine Jacoutot <ajacoutot@lphp.org>
To:        Bruno Afonso <brunomiguel@dequim.ist.utl.pt>, freebsd-ipfw@freebsd.org
Subject:   Re: ipfw dynamic rule timeout
Message-ID:  <200304291543.47991.ajacoutot@lphp.org>
In-Reply-To: <3EAE56E5.50208@dequim.ist.utl.pt>
References:  <200304271259.02025.ajacoutot@lphp.org> <200304290038.59573.ajacoutot@lphp.org> <3EAE56E5.50208@dequim.ist.utl.pt>

next in thread | previous in thread | raw e-mail | index | archive | help
On Tuesday 29 April 2003 12:41, Bruno Afonso wrote:
> http://marc.theaimsgroup.com/?l=freebsd-ipfw&r=1&w=2
> enjoy

OK, so after reading the archives, I saw that there was no solution to my 
problem, so what I did is:
sysctl net.inet.ip.fw.dyn_syn_lifetime=300
The default is 20, so it gives a little more time. But I still have problem 
from time to time (clients behind the firewall get disconnected from an 
internet news server after a while reading an article, web clients from the 
internet to the web server get disconnected while reading mail from 
webmail...).

Should I go like:
sysctl net.inet.ip.fw.dyn_syn_lifetime=100000000000000000
or is it just stupid ? (I'm sure this is stupid, but I can't find any 
solution).

Thanks a lot for your help.

Antoine



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200304291543.47991.ajacoutot>