Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort Error Bogon Rules

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    12 Posts 5 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      amarcino
      last edited by amarcino

      I have been experiencing the same issue with my 3100 since I upgraded it to 2.45 There are a few threads suggesting to up the Firewall maximum table entries however these changes did not work for me. Recently I read that this is a reported issue. I am ignoring the errors now, and hope that an update fixes the issue.

      Bug report

      styxlS 1 Reply Last reply Reply Quote 0
      • styxlS
        styxl @amarcino
        last edited by

        @amarcino i tried to increase the table entries also, didnt resolve the issue

        S 1 Reply Last reply Reply Quote 1
        • H
          HG
          last edited by HG

          I think I had a similar problem in an earlier pfSense version. The problem is, that probably also the rules that would come after that don't load?

          What you can try is to disable "Block bogon networks" in the interface settings of your WAN interfaces (and other interfaces, but I believe it's by default only enabled for WAN interfaces). I just saw that I still have it disabled, probably still from the issues I had back then.

          styxlS 1 Reply Last reply Reply Quote 1
          • styxlS
            styxl @HG
            last edited by

            @HG said in Snort Error Bogon Rules:

            I think I had a similar problem in an earlier pfSense version. The problem is, that probably also the rules that would come after that don't load?

            What you can try is to disable "Block bogon networks" in the interface settings of your WAN interfaces (and other interfaces, but I believe it's by default only enabled for WAN interfaces). I just saw that I still have it disabled, probably still from the issues I had back then.

            there is a lot of chatter using bogon networks on my WAN so i need those blocked, the rules do load eventually but you are right that sometimes they dont load at all

            1 Reply Last reply Reply Quote 1
            • S
              stompro @styxl
              last edited by

              @styxl Are you using ramdisks on your SG-3100?

              How much kmem do you have available (Diagnostics -> command prompt -> execute shell command "sysctl vm.kmem_map_free")

              I had one system where I saw this issue, I had my ramdisks set to use too much kernel memory, not leaving enough for the bogonsv6 reload. Seems to take 16MB - 34MB on my system to reload.

              This was on 2.4.5-p1 so the max table size was already increased by default to 400K, changing that had no effect for me. But freeing up kmem did help.

              Josh

              Hardware used: Alix 2D13 X 10, APU2D4 X 10, SG-2200 X 10, SG-2440 X 4

              styxlS 1 Reply Last reply Reply Quote 0
              • styxlS
                styxl @stompro
                last edited by

                @stompro

                i am not using RamDisk, its very weird but the issue disappers and shows up again after weeks....

                [2.4.5-RELEASE][papatee@Crier.local]/root: sysctl vm.kmem_map_free
                vm.kmem_map_free: 206639104

                1 Reply Last reply Reply Quote 1
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  What max table size value are you actually using? Do you have a lot of large tables loaded in pfBlocker or Snort?

                  styxlS 1 Reply Last reply Reply Quote 1
                  • styxlS
                    styxl @stephenw10
                    last edited by

                    @stephenw10

                    Max Table Value is set at "2000000", no large tables in SNORT

                    1 Reply Last reply Reply Quote 1
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Hmm, you are hitting this: https://redmine.pfsense.org/issues/10310
                      I'm not sure we've seen that on a 3100 before though. 2GB of RAM is usually sufficient.
                      As it says there though this is not actually due to exhausting the table size but in fact some other memory limit. I would set that back to the default 400K if it made no difference increasing it.

                      Steve

                      styxlS 1 Reply Last reply Reply Quote 1
                      • styxlS
                        styxl @stephenw10
                        last edited by

                        @stephenw10 sure, will give 400K a try and see. Thanks

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.