Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 27 Sep 2011 11:28:15 -0700
From:      Chuck Swiger <>
To:        =?iso-8859-1?Q?R=E9my_Sanchez?= <>
Subject:   Re: Random freezes
Message-ID:  <>
In-Reply-To: <>
References:  <>

Next in thread | Previous in thread | Raw E-Mail | Index | Archive | Help

On Sep 27, 2011, at 10:57 AM, R=E9my Sanchez wrote:
> The only solution we have so far : we just reload the rules, and =
> gets back to normal. Which is a bit unpleasant I must say...
> So, I've fallen short of ideas, does anyone see why some rules just =
block like=20
> that ? Maybe we should move to the in-kernel NAT ?

Sounds like you're running out of dynamic rule entries.

Check net.inet.ip.fw.dyn_count sysctl and increase =
net.inet.ip.fw.dyn_max as needed.  Also consider not using stateful =
rules for UDP traffic like DNS and NTP if at all possible...


Want to link to this message? Use this URL: <>