ipfw: Too many dynamic rules

Gareth de Vaux bsd at lordcow.org
Tue Sep 14 10:37:36 UTC 2010


On Fri 2010-09-10 (13:49), Gareth de Vaux wrote:
> > Thirdly, if you feel FIN_WAIT2 is the cause of your problem, then you
> > should consider adjusting the following sysctl:
> > 
> > net.inet.tcp.finwait2_timeout
> > 
> > Try something like 15000 (15 seconds) instead of the default (60000).
> 
> Ok that seems to be doing something. Will report back later.

Nope it's not helping. That and/or dropping net.inet.ip.fw.dyn_ack_lifetime.


More information about the freebsd-stable mailing list