[Bug 217997] [pf] orphaned entries in src-track

2017-03-29 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=217997 --- Comment #8 from Max --- I think the problem is in pf_create_state(): /* check maximums */ if (r->max_states && (counter_u64_fetch(r->states_cur) >= r->max_states)) { counter_u64_add(V_pf_stat

Re: When should I worry about performance tuning?

2017-03-29 Thread Chris H
On Thu, 30 Mar 2017 08:20:55 +1100 (EST) Dave Horsfall wrote > On Wed, 29 Mar 2017, Martin MATO wrote: > > > In the first case, you'll should prefer setting greylisting / tarpitting > > at minimum, feeding a firewall table for blacklisting is a neverending > > story (plus, there is some real c

re: When should I worry about performance tuning?

2017-03-29 Thread Dave Horsfall
On Wed, 29 Mar 2017, Martin MATO wrote: > In the first case, you'll should prefer setting greylisting / tarpitting > at minimum, feeding a firewall table for blacklisting is a neverending > story (plus, there is some real chance blocking real MX relays). A judicious selection of DNSBLs and enfo

Re: When should I worry about performance tuning?

2017-03-29 Thread Chris H
On Wed, 29 Mar 2017 22:57:48 +0200 (CEST) Martin MATO wrote > > Message du 29/03/17 22:05 > > De : "Chris H" > > A : "FreeBSD pf" > > Copie à : > > Objet : When should I worry about performance tuning? > > > > OK. My association with FreeBSD has made me a prime > > target for every male hormon

Re: When should I worry about performance tuning?

2017-03-29 Thread Chris H
On Wed, 29 Mar 2017 22:19:58 +0200 "Kristof Provost" wrote > On 29 Mar 2017, at 22:06, Chris H wrote: > > OK. My association with FreeBSD has made me a prime > > target for every male hormone distributor on the net. > > Fact is; I can guarantee ~89 SPAM attempts in under 5 > > minutes, after crea

re: When should I worry about performance tuning?

2017-03-29 Thread Martin MATO
Greetings. I don't understand some things. your machine is a mail relay/server, or you haved a host without any firewall between him and the internet?   In the first case, you'll should prefer setting greylisting / tarpitting at minimum, feeding a firewall table for blacklisting is a neverend

[Bug 217997] [pf] orphaned entries in src-track

2017-03-29 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=217997 --- Comment #7 from Max --- A bit more info... Before reaching the limit: Status: Enabled for 0 days 04:08:59 Debug: Urgent State Table Total Rate current entries 120

Re: When should I worry about performance tuning?

2017-03-29 Thread Kristof Provost
On 29 Mar 2017, at 22:06, Chris H wrote: OK. My association with FreeBSD has made me a prime target for every male hormone distributor on the net. Fact is; I can guarantee ~89 SPAM attempts in under 5 minutes, after creating a pr on bugzilla. At first I was angry, and frustrated. But decided to m

When should I worry about performance tuning?

2017-03-29 Thread Chris H
OK. My association with FreeBSD has made me a prime target for every male hormone distributor on the net. Fact is; I can guarantee ~89 SPAM attempts in under 5 minutes, after creating a pr on bugzilla. At first I was angry, and frustrated. But decided to make it a challenge/contest, and see my way

how to get daily statistics from periodic daily?

2017-03-29 Thread Chris H
Greetings, I've depended upon pf for many years, but somewhere between updating my servers from 9 to 11, and 12. I seem to have lost getting the daily statistics from pf. Does anyone know what changed, and what I need to do to get those reports back? Thanks! --Chris __

[Bug 217997] [pf] orphaned entries in src-track

2017-03-29 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=217997 --- Comment #6 from Robert Schulze --- (In reply to Max from comment #5) Thank you for your efforts. -- You are receiving this mail because: You are the assignee for the bug. ___ freebsd-pf@free