how much memory does increasing max rules for IPFW take up?

Andrey V. Elsukov bu7cher at yandex.ru
Thu May 15 09:52:40 UTC 2008


Vivek Khera wrote:
> I had a box run out of dynamic state space yesterday.  I found I can 
> increase the number of dynamic rules by increasing the sysctl parameter 
> net.inet.ip.fw.dyn_max.  I can't find, however, how this affects memory 
> usage on the system.  Is it dyanamically allocated and de-allocated, or 
> is it a static memory buffer?

Each dynamic rule allocated dynamically. Be careful, too many dynamic 
rules will work very slow.

-- 
WBR, Andrey V. Elsukov


More information about the freebsd-ipfw mailing list