Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Tcp.established changed on "System: Advanced: System Tunables" doesn't stick.

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kwag
      last edited by

      The subject says it all.
      I'm trying to change the default value of  tcp.established  which default value is  86400s

      I added tcp.established under the system tuneables, but even after a system reboot, it comes back up as 86400s.

      pfctl  -s timeouts
      
      tcp.first                   120s
      tcp.opening                  30s
      tcp.established           86400s
      tcp.closing                 900s
      

      etc. etc. etc.

      Am I missing something?

      Thanks,
      -Karl

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        That's not a system tunable. It's a pf timer.

        The only user-facing option that affects those is under System > Advanced on the Firewall/NAT tab, "Firewall Optimization". Conservative mode raises the timeout, Aggressive mode will lower the timeout.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • K
          kwag
          last edited by

          @jimp:

          That's not a system tunable. It's a pf timer.

          The only user-facing option that affects those is under System > Advanced on the Firewall/NAT tab, "Firewall Optimization". Conservative mode raises the timeout, Aggressive mode will lower the timeout.

          Ok. Thanks for responding.

          So, where can I change this pf timer and make the change persistent?
          I would like to lower the value to something like 1 hour.

          Thanks,
          -Karl

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            The only GUI option is the firewall optimization. There isn't any way to set it manually short of patching the code that produces the ruleset part that includes the timers.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.