• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[SOLVED] 2.4.3 - /rc.filter_configure_sync: cannot define table bogonsv6

Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
52 Posts 22 Posters 20.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    karlfife
    last edited by Apr 4, 2018, 2:39 AM

    April 3 2018 bogons:  100,001 rows

    ipv6 bogon prefixes 95,997
    ipv4 bogon prefixes 4004

    bogon table size: 100,001 rows

    If 2x are required to reload the table, then 200K seems slightly too small  ;)

    I now notice that my 2.4.2 systems are choking the same way as my freshly updated 2.4.3 systems if I both update bogons and reload the filter.

    1 Reply Last reply Reply Quote 0
    • V
      vMAC
      last edited by Apr 4, 2018, 3:02 PM

      New to pfSense and after installing 2.4.3 on a new install this popped up in my alerts.
      Unfortunately until I resolved this issue none of my port forwards would work at all.

      I bumped up the number of entries to 500,000 and my port forwards started working immediately.

      This is just an FYI in case you can't get your port forwards to work to anyone else who is very new to pfSense.

      1 Reply Last reply Reply Quote 0
      • B
        Bili_boy
        last edited by Apr 4, 2018, 10:12 PM

        The thing I don't understand is why it was 200K for you by default in the first place. I'm still on 2.3.4 and my default for "Firewall Maximum Table Entries" is 2M. (2 000 000). Did they reduce the default on purpose ?

        1 Reply Last reply Reply Quote 0
        • C
          cybrnook
          last edited by Apr 4, 2018, 11:37 PM

          Without going through the git revisions, I would say yes that somewhere between your release and the 2.4 releases it got changed to two hundred thousand 200,000. If you look at the link in the op for the bug ticket to get it fixed, the wording reads of changing the old default value of 200k to 400k. Letting you know that yes, 200k was the current default.

          What I am also thinking is that maybe some add on packages, like pfblocker or snort etc., change this default value to a higher number based off the nature of what new rules they will likely need. This is purely speculative.

          1 Reply Last reply Reply Quote 0
          • J
            jdeloach
            last edited by Apr 5, 2018, 12:53 AM

            @Bili_boy:

            The thing I don't understand is why it was 200K for you by default in the first place. I'm still on 2.3.4 and my default for "Firewall Maximum Table Entries" is 2M. (2 000 000). Did they reduce the default on purpose ?

            I've wondered the same thing.  I'm on 2.4.3 and the default for "Firewall Maximum Table Entries" is 2M (2,000,000) on my system.  I upgraded from 2.4.2 p1 but I don't remember what it was then and I don't remember ever changing it.  Not sure where all these people are getting that their system has 200K as default.

            1 Reply Last reply Reply Quote 0
            • C
              cybrnook
              last edited by Apr 5, 2018, 1:00 AM

              @jdeloach:

              @Bili_boy:

              The thing I don't understand is why it was 200K for you by default in the first place. I'm still on 2.3.4 and my default for "Firewall Maximum Table Entries" is 2M. (2 000 000). Did they reduce the default on purpose ?

              I've wondered the same thing.  I'm on 2.4.3 and the default for "Firewall Maximum Table Entries" is 2M (2,000,000) on my system.  I upgraded from 2.4.2 p1 but I don't remember what it was then and I don't remember ever changing it.  Not sure where all these people are getting that their system has 200K as default.

              what additional packages do you have installed?

              1 Reply Last reply Reply Quote 0
              • J
                jdeloach
                last edited by Apr 5, 2018, 1:14 AM

                @cybrnook:

                @jdeloach:

                @Bili_boy:

                The thing I don't understand is why it was 200K for you by default in the first place. I'm still on 2.3.4 and my default for "Firewall Maximum Table Entries" is 2M. (2 000 000). Did they reduce the default on purpose ?

                I've wondered the same thing.  I'm on 2.4.3 and the default for "Firewall Maximum Table Entries" is 2M (2,000,000) on my system.  I upgraded from 2.4.2 p1 but I don't remember what it was then and I don't remember ever changing it.  Not sure where all these people are getting that their system has 200K as default.

                what additional packages do you have installed?

                I only have the APC UPS Daemon package installed.  Everything else is just the default install.  I don't have any of the other packages like PfBlockerNG, Squid or Squidguard installed.

                1 Reply Last reply Reply Quote 0
                • C
                  cybrnook
                  last edited by Apr 5, 2018, 2:04 AM

                  @jdeloach:

                  @cybrnook:

                  @jdeloach:

                  @Bili_boy:

                  The thing I don't understand is why it was 200K for you by default in the first place. I'm still on 2.3.4 and my default for "Firewall Maximum Table Entries" is 2M. (2 000 000). Did they reduce the default on purpose ?

                  I've wondered the same thing.  I'm on 2.4.3 and the default for "Firewall Maximum Table Entries" is 2M (2,000,000) on my system.  I upgraded from 2.4.2 p1 but I don't remember what it was then and I don't remember ever changing it.  Not sure where all these people are getting that their system has 200K as default.

                  what additional packages do you have installed?

                  I only have the APC UPS Daemon package installed.  Everything else is just the default install.  I don't have any of the other packages like PfBlockerNG, Squid or Squidguard installed.

                  interesting. My install was just a vanilla 2.4.3. as soon as the config wizard was done, the error was already there.

                  1 Reply Last reply Reply Quote 0
                  • K
                    karlfife
                    last edited by Apr 5, 2018, 3:45 AM

                    Am I losing my mind?

                    I just updated another 2.4.2 system to 2.4.3, but noticed the new default is 400,000 entries whereas this thread started because the default was 200,000 entries just yesterday.  "Ah, they did a minor point-release and updated the default" I reasoned.

                    However, when I went to the machines that I'd manually overridden from 200,000 to 400,000 I noticed that their defaults had also changed, even though they have not been updated (i.e. via point-release).  Huh?  Aren't the defaults hard-coded into the release?

                    What I've seen here would be more consistent with the defaults being periodically fetched from somewhere.    Is that true?

                    1 Reply Last reply Reply Quote 0
                    • D
                      Derelict LAYER 8 Netgate
                      last edited by Apr 5, 2018, 3:59 AM

                      I haven't looked at the code but I think there is a logic problem in that "the system default is X." I think it just says whatever the field is set to instead of actually computing what the default would actually be.

                      For instance, I didn't see this overrun on bogonsv6 because mine was set to 2,000,000 by something/someone/probablyme. It said "the default on this system is 2,000,000"

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • K
                        karlfife
                        last edited by Apr 5, 2018, 4:08 AM

                        LOL.

                        By george you're right.  Looks like on my system, the "system default" looks a an awful lot like Pi, but I've overridden it to 400,000  ;)

                        piStatesCapture.PNG
                        piStatesCapture.PNG_thumb

                        1 Reply Last reply Reply Quote 0
                        • P
                          pfAmateur
                          last edited by Apr 5, 2018, 3:54 PM

                          As a beginner, thank you very much for your explanation!
                          I have set entries to 500K

                          500k.JPG
                          500k.JPG_thumb

                          1 Reply Last reply Reply Quote 0
                          • P
                            prbecker
                            last edited by Apr 8, 2018, 11:02 PM

                            I'd like to thank you all as well for explaining this! Very helpful in resolving this issue.

                            1 Reply Last reply Reply Quote 0
                            • S
                              Smoothrunnings
                              last edited by Apr 8, 2018, 11:16 PM

                              I guess the big question here is why?

                              Why do we need to increase the Firewall Maximum Table Entries from 200k (default) to 500k all of a sudden? I have been running pfSense a long time and have never had to make this change. So what changed all of a sudden?

                              It's great there is a solution but there isn't any real explanation as to why we have to change this value?

                              Thanks,

                              1 Reply Last reply Reply Quote 0
                              • D
                                Derelict LAYER 8 Netgate
                                last edited by Apr 8, 2018, 11:38 PM

                                The size of the IPv6 bogons table in the April update changed and pushed some systems over the edge.

                                The default has been changed to 400000 in 2.4.4

                                The timing of the bogons table monthly update and the release of 2.4.3 was simply coincidental.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • A
                                  AR15Dude
                                  last edited by Apr 9, 2018, 1:43 PM

                                  I'm confirming that after I upgraded from 2.4.2_1 to 2.4.3, I had the same type of error:

                                  Filter Reload
                                  There were error(s) loading the rules: /tmp/rules.debug:19: cannot define table bogonsv6: Cannot allocate memory - The line in question reads [19]: table <bogonsv6> persist file "/etc/bogonsv6"
                                  @ 2018-04-09 09:15:46

                                  Changing the Firewall Maximum Table Entries from 200000 to 500000 and rebooting solved the problem.

                                  1 Reply Last reply Reply Quote 0
                                  • E
                                    epalzeolithe
                                    last edited by Apr 9, 2018, 7:04 PM

                                    Tricky situation

                                    • if increase the maximum entries size from 200k to 400k, then rules modification and filters reload work without need of reboot

                                    • BUT, then i lose all my bandwidth, coming from 140Mb/s to 1Mb/s

                                    • if i use back 200k instead of 400k, then i have the bug back, but my bandwidth is back to 140mb/s !!!

                                    What the hell is that issue ???

                                    1 Reply Last reply Reply Quote 0
                                    • P
                                      pl0ink
                                      last edited by Apr 10, 2018, 12:45 AM Apr 9, 2018, 11:38 PM

                                      I have the same problem, even increased to 4,000,000, it does not make the error go away.
                                      Tried several values, increasing from default (listed as 200,000) to current 4,000,000 with reboots.

                                      Only solution i have for now is to "uncheck" the allow IPv6 Traffic in the System / Advanced / Networking section.
                                      No more errors.
                                      So i guess the bogonsv6 data is not loaded now?

                                      Have run PFSense for years without problems, 4 physical interfaces configured with about 10 VLANS, reasonable amount of rules, aliases etc.
                                      Should i continue to increase the number and try?  4,000,000 already seems excessive.

                                      1 Reply Last reply Reply Quote 0
                                      • D
                                        Derelict LAYER 8 Netgate
                                        last edited by Apr 10, 2018, 12:19 AM

                                        Your experience does not mirror countless others.

                                        Are you sure you are changing maximum table entries and not maximum states? They are completely different things.

                                        Chattanooga, Tennessee, USA
                                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                        1 Reply Last reply Reply Quote 0
                                        • P
                                          pl0ink
                                          last edited by Apr 10, 2018, 12:35 AM

                                          yes, i'm sure, did not touch the default for Max Firewall States.

                                          ![Screen Shot 2018-04-10 at 02.32.01.png](/public/imported_attachments/1/Screen Shot 2018-04-10 at 02.32.01.png)
                                          ![Screen Shot 2018-04-10 at 02.32.01.png_thumb](/public/imported_attachments/1/Screen Shot 2018-04-10 at 02.32.01.png_thumb)

                                          1 Reply Last reply Reply Quote 0
                                          40 out of 52
                                          • First post
                                            40/52
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received