Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    RuleError:There were errors loading the rules: /tmp/rules.debug:18: cannot alloc

    Scheduled Pinned Locked Moved General pfSense Questions
    25 Posts 17 Posters 67.7k Views 8 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      toms88
      last edited by

      Thanks all, il give that a try and see if it helps.

      1 Reply Last reply Reply Quote 0
      • K Offline
        kyawwinhtun
        last edited by

        @Derelict:

        Not hacking ffs.

        Do a forum search.

        Increase the Firewall Maximum Table Entries size to 400000 in System > Advanced, Firewall & NAT

        It Works Well!!!!!!Thanks  :D

        1 Reply Last reply Reply Quote 1
        • C Offline
          csandoval012
          last edited by

          mine is on default
          Maximum number of connections to hold in the firewall state table.
          Note: Leave this blank for the default. On this system the default size is: 4909000

          should I put more than that?

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            It is not the Firewall Maximum States entry it is the Firewall Maximum Table Entries setting. Set it to 400000.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • E Offline
              eddie4
              last edited by

              Jeej fixed my problem!!!!

              1 Reply Last reply Reply Quote 0
              • F Offline
                Floppie
                last edited by

                @Derelict:

                Not hacking ffs.

                Do a forum search.

                Increase the Firewall Maximum Table Entries size to 400000 in System > Advanced, Firewall & NAT

                This solved it for me after losing NAT port forwarding during a reboot this morning.  Thanks!

                1 Reply Last reply Reply Quote 0
                • I Offline
                  irfanit02gmail.com
                  last edited by

                  @Derelict:

                  Not hacking ffs.

                  Do a forum search.

                  Increase the Firewall Maximum Table Entries size to 400000 in System > Advanced, Firewall & NAT

                  =================================

                  Post increasing the Firewall Maximum Table Entries size to 400000 , all rules started working.. Thanks buddy.. i helped a lot..

                  1 Reply Last reply Reply Quote 0
                  • I Offline
                    itlogicsystems
                    last edited by

                    Thanks so much for the input!  the changing of the 'max table entries' size to 400k did the trick!!

                    1 Reply Last reply Reply Quote 0
                    • A Offline
                      aagaag
                      last edited by

                      Just wanted to say that I got the same message today, although my system says that its default is 6 million entries.

                      1 Reply Last reply Reply Quote 0
                      • DerelictD Offline
                        Derelict LAYER 8 Netgate
                        last edited by

                        Set it to 400000.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        B 1 Reply Last reply Reply Quote 0
                        • D Offline
                          DrRobe
                          last edited by

                          Worked perfectly, thank you!

                          1 Reply Last reply Reply Quote 0
                          • B Offline
                            Bon Jovi @Derelict
                            last edited by

                            @derelict hello, i have set it in 400000 and even don't work. Can you suggest any other solution, please?

                            1 Reply Last reply Reply Quote 0
                            • jimpJ Offline
                              jimp Rebel Alliance Developer Netgate
                              last edited by

                              Use a bigger number. Try 2000000.

                              If you have a lot of table entries (especially with pfBlockerNG) you might need that or more.

                              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                              Need help fast? Netgate Global Support!

                              Do not Chat/PM for help!

                              Sergei_ShablovskyS 1 Reply Last reply Reply Quote 3
                              • DerelictD Offline
                                Derelict LAYER 8 Netgate
                                last edited by

                                And be sure you're changing the right value. People, for some reason, seem to confuse Maximum States and Maximum Table Entries. Maximum Table Entries is what you want to change here.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • K Offline
                                  Khampol
                                  last edited by

                                  ok that works !
                                  ps : if i put it to 500000 ? is there any pb ? 😂

                                  1 Reply Last reply Reply Quote 0
                                  • DerelictD Offline
                                    Derelict LAYER 8 Netgate
                                    last edited by

                                    500000 should be fine.

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    K 1 Reply Last reply Reply Quote 1
                                    • K Offline
                                      Khampol @Derelict
                                      last edited by

                                      @Derelict Ok got it. Thx ! :)

                                      1 Reply Last reply Reply Quote 1
                                      • Sergei_ShablovskyS Offline
                                        Sergei_Shablovsky @jimp
                                        last edited by

                                        @jimp said in RuleError:There were errors loading the rules: /tmp/rules.debug:18: cannot alloc:

                                        Use a bigger number. Try 2000000.

                                        If you have a lot of table entries (especially with pfBlockerNG) you might need that or more.

                                        How this value correspond or depend to total amount of avail for FreeBSD system memory ?

                                        Please point me on a source where described in details how important for network operations resources like

                                        • NICs controllers (CPU, memory on controllers, number of Eth ports on each controller);
                                        • whole appliance memory amount;
                                        • main appliance CPU;
                                          and
                                        • memory/network/cpu core settings in FreeBSD;
                                          influence on pfSense speed, troughtput and stability of operation.

                                        Common words are less interesting than numbers, of course :)

                                        Thank You!

                                        —
                                        CLOSE SKY FOR UKRAINE https://youtu.be/_tU1i8VAdCo !
                                        Help Ukraine to resist, save civilians people’s lives !
                                        (Take an active part in public protests, push on Your country’s politics, congressmans, mass media, leaders of opinion.)

                                        1 Reply Last reply Reply Quote 1
                                        • jimpJ Offline
                                          jimp Rebel Alliance Developer Netgate
                                          last edited by

                                          Make your own thread instead of posting to a mostly-irrelevant nearly year-old thread.

                                          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                                          Need help fast? Netgate Global Support!

                                          Do not Chat/PM for help!

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.