Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort Error Bogon Rules

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    12 Posts 5 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • styxlS
      styxl
      last edited by

      There were error(s) loading the rules: /tmp/rules.debug:20: cannot define table bogonsv6: Cannot allocate memory - The line in question reads [20]: table <bogonsv6> persist file "/etc/bogonsv6"
      @ 2020-04-30 19:35:43

      1 Reply Last reply Reply Quote 0
      • A
        amarcino
        last edited by amarcino

        I have been experiencing the same issue with my 3100 since I upgraded it to 2.45 There are a few threads suggesting to up the Firewall maximum table entries however these changes did not work for me. Recently I read that this is a reported issue. I am ignoring the errors now, and hope that an update fixes the issue.

        Bug report

        styxlS 1 Reply Last reply Reply Quote 0
        • styxlS
          styxl @amarcino
          last edited by

          @amarcino i tried to increase the table entries also, didnt resolve the issue

          S 1 Reply Last reply Reply Quote 1
          • H
            HG
            last edited by HG

            I think I had a similar problem in an earlier pfSense version. The problem is, that probably also the rules that would come after that don't load?

            What you can try is to disable "Block bogon networks" in the interface settings of your WAN interfaces (and other interfaces, but I believe it's by default only enabled for WAN interfaces). I just saw that I still have it disabled, probably still from the issues I had back then.

            styxlS 1 Reply Last reply Reply Quote 1
            • styxlS
              styxl @HG
              last edited by

              @HG said in Snort Error Bogon Rules:

              I think I had a similar problem in an earlier pfSense version. The problem is, that probably also the rules that would come after that don't load?

              What you can try is to disable "Block bogon networks" in the interface settings of your WAN interfaces (and other interfaces, but I believe it's by default only enabled for WAN interfaces). I just saw that I still have it disabled, probably still from the issues I had back then.

              there is a lot of chatter using bogon networks on my WAN so i need those blocked, the rules do load eventually but you are right that sometimes they dont load at all

              1 Reply Last reply Reply Quote 1
              • S
                stompro @styxl
                last edited by

                @styxl Are you using ramdisks on your SG-3100?

                How much kmem do you have available (Diagnostics -> command prompt -> execute shell command "sysctl vm.kmem_map_free")

                I had one system where I saw this issue, I had my ramdisks set to use too much kernel memory, not leaving enough for the bogonsv6 reload. Seems to take 16MB - 34MB on my system to reload.

                This was on 2.4.5-p1 so the max table size was already increased by default to 400K, changing that had no effect for me. But freeing up kmem did help.

                Josh

                Hardware used: Alix 2D13 X 10, APU2D4 X 10, SG-2200 X 10, SG-2440 X 4

                styxlS 1 Reply Last reply Reply Quote 0
                • styxlS
                  styxl @stompro
                  last edited by

                  @stompro

                  i am not using RamDisk, its very weird but the issue disappers and shows up again after weeks....

                  [2.4.5-RELEASE][papatee@Crier.local]/root: sysctl vm.kmem_map_free
                  vm.kmem_map_free: 206639104

                  1 Reply Last reply Reply Quote 1
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    What max table size value are you actually using? Do you have a lot of large tables loaded in pfBlocker or Snort?

                    styxlS 1 Reply Last reply Reply Quote 1
                    • styxlS
                      styxl @stephenw10
                      last edited by

                      @stephenw10

                      Max Table Value is set at "2000000", no large tables in SNORT

                      1 Reply Last reply Reply Quote 1
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Hmm, you are hitting this: https://redmine.pfsense.org/issues/10310
                        I'm not sure we've seen that on a 3100 before though. 2GB of RAM is usually sufficient.
                        As it says there though this is not actually due to exhausting the table size but in fact some other memory limit. I would set that back to the default 400K if it made no difference increasing it.

                        Steve

                        styxlS 1 Reply Last reply Reply Quote 1
                        • styxlS
                          styxl @stephenw10
                          last edited by

                          @stephenw10 sure, will give 400K a try and see. Thanks

                          1 Reply Last reply Reply Quote 1
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.