Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG4860 alert message "Cannot allocate memory"

    Scheduled Pinned Locked Moved General pfSense Questions
    13 Posts 4 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SenseiNYC
      last edited by

      The error reads:

      There were error(s) loading the rules: /tmp/rules.debug:22: cannot define table bogonsv6: Cannot allocate memory - The line in question reads [22]: table <bogonsv6> persist file "/etc/bogonsv6"

      Is there an easy fix for this?

      Thanks.

      1 Reply Last reply Reply Quote 0
      • chrismacmahonC
        chrismacmahon
        last edited by

        what version are you running?

        Need help fast? Our support is available 24/7 https://www.netgate.com/support/

        Do Not PM For Help!

        1 Reply Last reply Reply Quote 0
        • S
          SenseiNYC
          last edited by

          2.4.3

          1 Reply Last reply Reply Quote 0
          • chrismacmahonC
            chrismacmahon
            last edited by

            I would update to the latest, 2.4.4-p2, but you can set a manual limit like in this thread: https://forum.netgate.com/topic/129047/see-here-for-this-error-cannot-define-table-bogonsv6-cannot-allocate-memory/

            Need help fast? Our support is available 24/7 https://www.netgate.com/support/

            Do Not PM For Help!

            1 Reply Last reply Reply Quote 0
            • S
              SenseiNYC
              last edited by

              right i read the thread, where do i set the limit? also if i am not using ipv6 couldn't i disable v6 bogons?

              1 Reply Last reply Reply Quote 0
              • chrismacmahonC
                chrismacmahon
                last edited by chrismacmahon

                I would not disable bogons of any sort.

                If you navigate to System -> Advanced -> Firewall & NAT tab, you should see a section called Firewall Maximum Table Entries, feel free to bump that up.

                My SG-4860 is at 4000000.

                Need help fast? Our support is available 24/7 https://www.netgate.com/support/

                Do Not PM For Help!

                1 Reply Last reply Reply Quote 0
                • S
                  SenseiNYC
                  last edited by

                  the default value for max tables entries is 400k so that didn't work well. Is there a rule of thumb about how much memory let's say 1k tables will consume?

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by johnpoz

                    Did you update?

                    Im am running sg4860, and yes the default is 400k for the table size. Not having any issues.

                    You have 2 options to be currently support
                    2.4.4p1 previous release, or current 2.4.4p2

                    If you are on 2.4.3 your not currently supported version..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • S
                      SenseiNYC
                      last edited by

                      Actually it was 2.4.4-p2 already I was wrong. Problem is that I was forced to run 80 miles over to the site because the manager decided to manually reboot. The SG4860 never came back up. It was available via SSH, HTTP never came back. So sadly I had to factory reset and start all over without having the benefit of troubleshooting the problem.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        so your good now - your not having bogon problem?

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • S
                          SenseiNYC
                          last edited by

                          lol exactly.

                          1 Reply Last reply Reply Quote 0
                          • S
                            SenseiNYC
                            last edited by

                            maybe it has something to do with me loading over 200k rows for blocking port 25 from the WAN via Alias (ip table) as well as having lite squid installed as well as pfblocker? bah who knows. i would like to be able to use me own IP blocks which i created from various sources. i dont think i'll want to load all 330k rows but i would like to be able to use my sources.

                            1 Reply Last reply Reply Quote 0
                            • DerelictD
                              Derelict LAYER 8 Netgate
                              last edited by

                              Yeah if you are loading another 200K rows you might have to increase that value.

                              It is in System > Advanced, Firewall & NAT, Firewall Maximum Table Entries

                              400K is enough by default. With your extra 200K I'd try 600K

                              Chattanooga, Tennessee, USA
                              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                              Do Not Chat For Help! NO_WAN_EGRESS(TM)

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.