• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Rule state timeout

Scheduled Pinned Locked Moved Firewalling
4 Posts 2 Posters 3.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    theflakes
    last edited by Jul 3, 2012, 5:50 AM Jul 3, 2012, 5:45 AM

    I've set a state timeout of 300 seconds for our student networks.  When I look at pfTop the IN state has the right timeout value, but the OUT state still shows the aggressive value of 18,000.  This leaves a lot of OUT states waiting to expire after the IN state has long expired.  Two questions:

    How can I have the OUT states use the rule set state timeout of 300 seconds instead of the default system state timeout of 18,000?

    If the above cannot be done will this cause issues with the max-src-states and max-src connection directives, or do those only count IN state table entries?

    I've tried setting the state timeout on LAN and Floating rules with the same results.

    thanks

    1 Reply Last reply Reply Quote 0
    • T
      theflakes
      last edited by Jul 4, 2012, 2:08 PM

      From the research I've done it does not seem it is possible to change the OUT state timeout.

      1 Reply Last reply Reply Quote 0
      • J
        jimp Rebel Alliance Developer Netgate
        last edited by Jul 8, 2012, 6:55 PM

        Add a floating rule to pass quick in the 'out' direction on the interface the traffic will leave (or any interface) with the same source/destination, and set the timeout there also.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • T
          theflakes
          last edited by Jul 8, 2012, 10:50 PM

          Thanks

          Unfortunately it breaks any connection.  The following is what I defined on the floating rule:

          pass:apply immediately:tcp:same source: same dest(any):300 timeout for state

          With the above rule active tcp connection never reach established:established.  I tried multiple variations on this rule with no success.

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received