dyn buckets

Don Bowman don at sandvine.com
Fri Sep 10 12:51:50 PDT 2004


From: owner-freebsd-net at freebsd.org
> I have a firewall running 4.10 that handles around 
> 20mbits/sec of traffic 
> and has around 500 ipfw rules.
> 
> Lately I've noticed that net.inet.ip.fw.curr_dyn_buckets 
> seems to be maxing 
> out.  I've increased net.inet.ip.fw.dyn_buckets a few times, 
> but they seem 
> to max out each time.
> 
> Is there any problem with increasing 
> net.inet.ip.fw.dyn_buckets far beyond 
> the default?  (I'm at 2048 now)

I use 
net.inet.ip.fw.dyn_buckets=16384
net.inet.ip.fw.dyn_syn_lifetime=5
net.inet.ip.fw.dyn_max=32000




More information about the freebsd-net mailing list