Pfblocker strange problem: out of memory, not loading rules
-
I encountered a strange problem with pfblocker on ad64, pfSense v2.1.5.
I get the message at the dashboard:php: rc.filter_configure_sync: New alert found: There were error(s) loading the rules: /tmp/rules.debug:38: cannot define table pfBlockerRussen: Cannot allocate memory - The line in question reads [38]: table <pfblockerrussen> persist file "/var/db/aliastables/pfBlockerRussen.txt"</pfblockerrussen>
The dashboard shows 28% memory used (4GB installed) imbf usage is low by about 14%, state table shows 0% used, all the pfblocker aliases show green, but apparently all internet is gone.
The whole thing appears every time when an IP-change (ISP disconnect) happens.
Restarting pfblocker resolves the problem.
I have snort, avahi, cups, squid 3.3.1 and squidguard installed. So far no other problems here.
-
Although its been a while since your question, maybe its still useful to answer . I found somewhere on this forum that increasing Firewall Maximum Table Entries (its under system>advanced>Firewall/NAT) solves the problem of loading the blocking rules. Personally I increased it to 20000000 without problem but maybe even 1/10 of that is fine.
John