• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Pfsense lockup?!?!? state table SOLUTION

Scheduled Pinned Locked Moved Firewalling
9 Posts 7 Posters 6.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    bruor
    last edited by Dec 29, 2005, 8:35 PM

    ok,  figured i would post here because this was a rather annoying issue to figure out.

    it seems that my simple home network, 2 pc's and only 1 machine running bittorrent (only around 3 torrents at one time) plus a voip phone, was causing pfsense to lock up

    at first i thought it was the hardware becasue there was no entry in the logs under system or firewall that gave me any clue to what the unresponsiveness of the unit might be caused by.  it would seem that every 100th try (overexaggerating) would get through the firewall for web browsing etc, but the bittorrent downloads would no lock up at all.  everyday i would reset the firewall, and it would work for around a day, and would be dead by the next morning

    i finally tracked it down to the amount of states that the firewall holds, watching the state table size grow, it would average around a 20 state per second growth rate at the default expiration setting.  moving this to conservative made this rate boom,  and aggressive seems like it is expiring the connections down from around 15000 at a rate of 10/sec

    just a tip for anyone out there,  make sure to set your unit to aggressive if you are gonna run filesharing.  or if someone can tell me if i have something misconfigured elsewhere, i would greatly appreciate it.

    hope this helps ;)

    1 Reply Last reply Reply Quote 0
    • S
      sullrich
      last edited by Dec 29, 2005, 8:38 PM

      With 150+ users behind one pfsense we rarely even see 10,000 states.  You must be the warez king over there.

      1 Reply Last reply Reply Quote 0
      • L
        lsf
        last edited by Jan 3, 2006, 5:01 PM

        Maybe it's bittorrent, it's eating a lot of states iirc.

        -lsf

        1 Reply Last reply Reply Quote 0
        • E
          epsilon
          last edited by Jan 11, 2006, 11:42 PM

          its like your at my place,

          2 computers
          a vonage box
          1 computer running bittorren

          I was thinking hardware as well till i went thou 4 computers last one being a dule amd MP2400+ with 2gigs of ram
          was trying of over kill still went dead after about 24hours. some times as little as 4 hours if i was doing a massive anime download.

          I'll try changing my settings to aggressive

          thanks.

          1 Reply Last reply Reply Quote 0
          • B
            billm
            last edited by Jan 11, 2006, 11:53 PM

            Wierd, I never have a problem with my 4801 and bittorrent.  Of course I also have my state table set to 50000 :)

            –Bill

            pfSense core developer
            blog - http://www.ucsecurity.com/
            twitter - billmarquette

            1 Reply Last reply Reply Quote 0
            • L
              Leoandru
              last edited by Jan 12, 2006, 12:25 AM

              have mine set to 65536.. Its been going for weeks only rebooting on upgrades.. No problems and we run bittorrent on a regular basis.

              1 Reply Last reply Reply Quote 0
              • Z
                ZGamer
                last edited by Jan 27, 2006, 3:39 PM

                The interesting problem I find is that after a day or two with the 3 computers on my network I can get this problem without any p2p applications but if I switch to m0n0 is seems to handle it just fine, the only difference which it may be the source of the problem is the atheros pci card which is in the firewall….possibly failing to close states(haven't verified yet).

                –------------------------------------------------------------------------------------
                pfSense Documentation Wiki
                Need Commercial Support?
                Personal Blog

                1 Reply Last reply Reply Quote 0
                • S
                  sullrich
                  last edited by Jan 27, 2006, 5:19 PM

                  Aren't you comparing apples to oranges?  Last time I checked m0n0wall doesn't support atheros.

                  1 Reply Last reply Reply Quote 0
                  • Z
                    ZGamer
                    last edited by Jan 28, 2006, 1:56 AM

                    @sullrich:

                    Aren't you comparing apples to oranges?  Last time I checked m0n0wall doesn't support atheros.

                    True, m0n0wall doesn't support Atheros. I need to check this with the atheros card removed.

                    –------------------------------------------------------------------------------------
                    pfSense Documentation Wiki
                    Need Commercial Support?
                    Personal Blog

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received