Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot define table bogonsv6: Cannot allocate memory

    Scheduled Pinned Locked Moved 2.1 Snapshot Feedback and Problems - RETIRED
    13 Posts 7 Posters 37.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      wallabybob
      last edited by

      @jimp:

      You might need to bump the max table entries under System > Advanced, Firewall/NAT tab.

      And reboot for the change to take effect?

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        I thought on 2.1 the way we did it now it didn't need a reboot, but a reboot would ensure it took.

        Alternately,

        pfctl -FT
        

        And then trigger a filter reload.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • M
          markuhde
          last edited by

          I had the same issue about a week ago and upon a reboot (with a larger filter table based on old searches), PPPoE was completely dead (I disabled the interface, enabled it as a static IP, disabled it, enabled it as PPPoE to get it to work again). I updated in hopes newer snapshots solved whatever glitch happened, tho newer snapshots have broke PPPoE. Planning to update again this week since traffic shaping on VLANs is fixed. We shall see what happens :D

          1 Reply Last reply Reply Quote 0
          • D
            dominique.fournier
            last edited by

            @jimp:

            how many lines are in that file? ย (wc -l /etc/bogonsv6)

            You might need to bump the max table entries under System > Advanced, Firewall/NAT tab.

            Hi There is ย 56466 lines in the file, and the value for the entries is 100000, far away from 56466โ€ฆ

            2.1 (amd64)

            1 Reply Last reply Reply Quote 0
            • D
              databeestje
              last edited by

              Ah, yes, but if you exactly double that number you will go above the 100k entries.

              On filter reload the new one is loaded before the old is purged resulting in this behaviour. Up it to 150k and it should work again.

              1 Reply Last reply Reply Quote 0
              • D
                dominique.fournier
                last edited by

                OK : I put 200000 and it works. Maybe a bug should be opened to put this new value by default ?

                I don't reboot the box, it is not needed.

                2.1 (amd64)

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  The default is 200,000 on the box I'm staring at here. Not sure how it would have defaulted lower unless it was explicitly set there. I don't think we auto-tune that one, but if we do, it would be set to 10% of your RAM (So 200,000 = 200MB)

                  Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • rcfaR
                    rcfa
                    last edited by

                    @jimp:

                    The default is 200,000 on the box I'm staring at here. Not sure how it would have defaulted lower unless it was explicitly set there. I don't think we auto-tune that one, but if we do, it would be set to 10% of your RAM (So 200,000 = 200MB)

                    Something seems to be done automatically. I never set it (empty field) and the text next to it says:

                    Firewall Maximum Table Entries
                    Maximum number of table entries for systems such as aliases, sshlockout, snort, etc, combined.
                    Note: Leave this blank for the default. On your system the default size is: 100000

                    Now, my system has 4GB RAM, and a dual-core 64-bit Atom D510 CPU (hyperthreading, too).
                    So by your recommendation, I should up this to 400000?

                    While on the subject, can the other defaults on that page be "trusted", or should they also be based on system configuration, and if so, what's the rule of thumb for those values?

                    1 Reply Last reply Reply Quote 0
                    • jimpJ
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      There is no rule of thumb, the defaults are fine for most. If you need more table entries, you can increase it, but most people don't.

                      Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • D
                        dominique.fournier
                        last edited by

                        @jimp:

                        There is no rule of thumb, the defaults are fine for most. If you need more table entries, you can increase it, but most people don't.

                        I understand, but I just activate IPv6 and IPv4 bogons. No more.
                        So I think it is a bug if just after installation, I can't activate bogons at all.

                        I note the step for the next time. Thanks !

                        2.1 (amd64)

                        1 Reply Last reply Reply Quote 0
                        • W
                          weekleyj
                          last edited by

                          I've got a similar box an Atom D525 with 4 GB RAM, 400000 seems to work well.

                          1 Reply Last reply Reply Quote 0
                          • S SteveITS referenced this topic on
                          • patient0P patient0 referenced this topic on
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.