Config validation very slow with 7000+ NATs

  • Hi,
    I have a pfSense VM (2.4.2) running on 4 Xeon E5-2630 cores and 6 GiB of RAM. The firewall works well most of the time, config changes take 1 or 2 seconds.
    However, when I add 7000 NATs, the Web UI becomes really slow every time I change something. php-fpm is using 100% CPU for about a minute and the Web UI is unresponsive, even though I increased the max number of processes.

    I understand that this is due to the config being validated or cached and my CPU may not have amazing performance in single threaded mode but still, can't we do anything about this?
    It would still be acceptable if the problem occured only when I edit NATs but editing any part of the config takes at least one minute.

    Please let me know if I should open an issue in the tracker.

  • Open a ticket.  I don't know if anyone outside of Netgate would have experience with that many NATs.

Log in to reply