Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 12 Apr 2001 10:01:44 -0700
From:      Gregory Neil Shapiro <gshapiro@FreeBSD.ORG>
To:        Lyndon Nerenberg <>
Cc:        freebsd-ipfw@FreeBSD.ORG
Subject:   Re: ipfw dynamic rulesets broken for me 
Message-ID:  <>
In-Reply-To: <>
References:  <> <>

Next in thread | Previous in thread | Raw E-Mail | Index | Archive | Help
lyndon> ipfw has insanely short timeouts for the keep-state engine.

A note to the ipfw maintainers, this should work out of the box so it's
less of a support hassle.

lyndon> Add this to /etc/sysctl.conf (adjusted to a suitable value
lyndon> for your network):

lyndon> # TCP connections time out after eight hours.
lyndon> net.inet.ip.fw.dyn_ack_lifetime=28800

Thanks, I'll give it a try and see if it solves all of the problems.

To Unsubscribe: send mail to
with "unsubscribe freebsd-ipfw" in the body of the message

Want to link to this message? Use this URL: <>