Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Zone: pf states limit reached?

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    14 Posts 2 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bokikay @Derelict
      last edited by

      @Derelict thank you sir. How much Firewall Maximum States would be needed sir? Is there any recommendation number of the states needed? Thank you

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        If you are reaching maximum states, it will be up to you to determine why and what a reasonable limit is. What is the maximum state value in your environment? Why is it so high?

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        B 1 Reply Last reply Reply Quote 1
        • B
          bokikay @Derelict
          last edited by

          @Derelict thank you sir, I have 5 laboratories inside sir and each lab has 35 workstation, and in offices there are 60+ computers. I did not fill in any number in the maximum states I leave it blank as a default.

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by Derelict

            So what is that number? How many states are active when you get that error? What are those workstations doing? You can view historical total states in Status > Monitoring. How much RAM?

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            B 1 Reply Last reply Reply Quote 1
            • B
              bokikay @Derelict
              last edited by

              @Derelict 1d2dd7db-011a-4265-ac71-064985efd67b-image.png this is the monitoring graph sir, I have 8GB RAM installed. Those workstation are used for browsing only.

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                Show us states. Change the left axis to System and the graph to states. click the wrench at the upper right.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                B 1 Reply Last reply Reply Quote 1
                • B
                  bokikay @Derelict
                  last edited by

                  @Derelict this one sir c022628d-acb4-4b9c-8bf7-ec4e042a4780-image.png

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    It looks like you have significant stability problems there. 300 state changes is nothing. literally nothing. Not sure why you disabled showing total states though. I would be looking for faulty hardware based on that.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    B 1 Reply Last reply Reply Quote 1
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      640K max states is significant though. You would want to find the reason for that. With 8GB setting max states to something like 2,000,000 would not break anything in and of itself. But 640K states is a lot if you don't know why they are there.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      B 1 Reply Last reply Reply Quote 1
                      • B
                        bokikay @Derelict
                        last edited by

                        @Derelict aa630f91-34d3-45f2-85b1-aa70c71ba73a-image.png

                        1 Reply Last reply Reply Quote 0
                        • B
                          bokikay @Derelict
                          last edited by

                          @Derelict Thank you for your time sir. It seems like it works fine right now. Thumbs up sir thanks a lot.

                          1 Reply Last reply Reply Quote 0
                          • DerelictD
                            Derelict LAYER 8 Netgate
                            last edited by

                            That is a lot of states. Does it make sense that those all exist in your environment?

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 1
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.