Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Maximum Firewall States

    Scheduled Pinned Locked Moved NAT
    4 Posts 3 Posters 6.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • X
      xphat
      last edited by

      Hello :)

      New member on the forums.. Anyhow.. to question..

      What is the maximum figure that can be put in the advanced page for the maximum number of firewall states..
      My max was set to 40,000 states and it was filling up so i set it to 60,000 states.
      My box has enough memory (1Gig) and processing power (2.8Ghz)
      so i want to know whats the theoretical maximum (if any)

      Thanks

      1 Reply Last reply Reply Quote 0
      • Z
        ZGamer
        last edited by

        Just keep an eye on your cpu and memory usage, if they arn't maxed out you have more to go.

        –------------------------------------------------------------------------------------
        pfSense Documentation Wiki
        Need Commercial Support?
        Personal Blog

        1 Reply Last reply Reply Quote 0
        • B
          billm
          last edited by

          @xphat:

          Hello :)

          New member on the forums.. Anyhow.. to question..

          What is the maximum figure that can be put in the advanced page for the maximum number of firewall states..
          My max was set to 40,000 states and it was filling up so i set it to 60,000 states.
          My box has enough memory (1Gig) and processing power (2.8Ghz)
          so i want to know whats the theoretical maximum (if any)

          Thanks

          Rough rule of thumb is each state takes about 1K of RAM.  With a gig, you should be able to hit 768K states (I'm reserving 256M for OS and userland, a little excessive, but fair, IMO).

          –Bill

          pfSense core developer
          blog - http://www.ucsecurity.com/
          twitter - billmarquette

          1 Reply Last reply Reply Quote 0
          • X
            xphat
            last edited by

            Thanks Billm :)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.