Hi there,
first the good news: the problem really seemes to be gone - at least it did not occur again since updating to the snapshot mentioned in my last post.
However, the reason why that is so, is still in the dark.
I changed since then only two things:
updated the states to 500000
updated the image.
Regarding states, I see even in heaviest times like 1000-2000 states - this is still very, very far away from even the standard 10000.
Again here my setup:
Internet routing x.y.z.w/25 , GW x.y.z.129 –--- x.y.z.130 (WAN-IF)---pfsense (transparent bridge mode)-----x.y.z.135 (LAN_IF)------ clients in the range x.y.z.w/25 via DHCP (without the used ones)
I agree that the blocked traffic looks like out-of-state; however, when the situation occured the GUI showed me much less states than have beeen configured.
Anyway.. for now the problem is solved and i hope it stays like that. If it will re-occur, I'll try to give even more details.
Best regards and keep up the good work!
Arno