Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Questions on State Timeouts

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 2 Posters 279 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JonathanLeeJ
      JonathanLee
      last edited by JonathanLee

      Has anyone else custom adapted the default state timeouts for a 2100-MAX?

      Screenshot 2025-06-06 at 12.52.19.png

      This seems to work a lot better with gaming and streaming with use of Snort, Squid, Squidguard, and upnp usage.

      Screenshot 2025-06-06 at 12.49.41.png

      Let me know what you think.

      This one in particular
      UDP Multiple 300 Long-lasting bidirectional flows like VoIP, game traffic, or UPnP

      Make sure to upvote

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        With timeouts that long you could end up with a lot more states in the table. Potentially you could end up exhausting the RAM. That depends on how much traffic you have of course.

        I would watch the state table size for a bit to be sure it doesn't grow too huge.

        JonathanLeeJ 1 Reply Last reply Reply Quote 1
        • JonathanLeeJ
          JonathanLee @stephenw10
          last edited by

          @stephenw10 what about this is this better?

          "Summary of Xbox Timeouts (for optimal gaming experience)
          Protocol State Type Recommended Timeout
          UDP First 120 seconds
          Single 120 seconds
          Multiple 120 seconds
          TCP Established 86,400 seconds (24 hours)
          Closing 900 seconds (15 minutes)
          Opening 30 seconds
          ICMP First 20 seconds
          Error 10 seconds
          This setup will provide the best balance of long-lived connections (important for real-time gaming and services like Xbox Live) while still keeping the firewall efficient"

          Make sure to upvote

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            If it works better for XBox live then sure. 😁

            I don't have one to test so I can't really comment. Just be aware that anything you do to make states last longer is going to increase the total state count at any time. That might be no problem for you with 4G to play with. In many use cases it would be though.

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.