Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Save states across reboot?

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 3 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      sporkme
      last edited by

      I remember at some point having a BSD-based firewall that let you run a command at shutdown to save firewall/NAT states to a file and then load them back at system start.  After a bit of googling, it looks like this was the old "ipf" firewall package, and specifically the "ipfs" command (https://smartos.org/man/1m/ipfs).

      It appears pf dropped this capability - I don't see anything in the pfctl manpage to lock, save or load states.  So long shot, any plans for pfsense to do something similar since you're working with a sort of fork of the official pf?  I remember how nice it was to be able to keep my ssh sessions around over the course of an OS update, how cool would that be if one could start an update in pfsense and when the box finishes rebooting all your long-running connections are still there?

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        No plans that I'm aware of. If session integrity is that important you should setup HA using CARP+pfsync so the states are synchronized to a secondary node and then synchronized back when the first node recovers.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • H Offline
          Harvy66
          last edited by

          Unless your router can reboot in 24 seconds, you're probably going to have a large porting of your TCP connection timeout. Few protocols will except 100% loss during a reboot. Little benefit to saving states.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.