Project

General

Profile

Actions

Bug #13366

open

Under or over size state tables cause pfctl error ``DIOCSETSYNCOOKIES``

Added by Christopher Cope almost 2 years ago. Updated almost 2 years ago.

Status:
New
Priority:
Low
Assignee:
-
Category:
Rules / NAT
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

On systems with excessively large RAM, where the default state table is huge the following error is seen and traffic is not filtered or logged.

There were error(s) loading the rules: pfctl: DIOCSETSYNCOOKIES - The line in question reads [0]: @ 2022-07-19 13:56:03

I've only seen 2 cases of this so far. The last customer mentioned it was working fine in 2.5.2 before the upgrade to 2.6. The other one was on 22.01.

The fix is to set the maximum states to a reasonable amount. 32600000 worked in this case.

Maybe this should be capped at a certain maximum default value regardless of RAM?

Actions

Also available in: Atom PDF