Re: ipfw2 problem

2004-01-04 Thread Leo Bicknell
In a message written on Sun, Jan 04, 2004 at 05:32:17PM +0800, Ganbold wrote: > me what will happen when net.inet.ip.fw.dyn_count reaches > net.inet.ip.fw.dyn_max value? As a random passing thought... Anytime a new dynamic rule is denied due to reaching dyn_max, a new counter, eg, "dropped_dyn_

RE: ipfw2 problem

2004-01-04 Thread Ganbold
Hi, How much memory does your machine have? I have never tried ipfw with -d option. I'll try next time. Actually one_pass is already turned off in sysctl.conf Any other recommendations? One suggested me to remove keep-state from http filtering rules. Will it solve the problem? Ganbold At 01:41 AM