Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
pfSense Forum
pfSense English Support
»
Firewalling
»
rule state timeout
Username:
Password:
1 Hour
1 Day
1 Week
1 Month
Forever
Home
Help
Search
Login
Register
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: rule state timeout (Read 808 times)
0 Members and 1 Guest are viewing this topic.
theflakes
Newbie
Offline
Posts: 17
rule state timeout
«
on:
July 03, 2012, 12:45:30 am »
I've set a state timeout of 300 seconds for our student networks. When I look at pfTop the IN state has the right timeout value, but the OUT state still shows the aggressive value of 18,000. This leaves a lot of OUT states waiting to expire after the IN state has long expired. Two questions:
How can I have the OUT states use the rule set state timeout of 300 seconds instead of the default system state timeout of 18,000?
If the above cannot be done will this cause issues with the max-src-states and max-src connection directives, or do those only count IN state table entries?
I've tried setting the state timeout on LAN and Floating rules with the same results.
thanks
«
Last Edit: July 03, 2012, 12:50:33 am by theflakes
»
Logged
theflakes
Newbie
Offline
Posts: 17
Re: rule state timeout
«
Reply #1 on:
July 04, 2012, 09:08:22 am »
From the research I've done it does not seem it is possible to change the OUT state timeout.
Logged
jimp
Administrator
Hero Member
Offline
Posts: 12863
Re: rule state timeout
«
Reply #2 on:
July 08, 2012, 01:55:08 pm »
Add a floating rule to pass quick in the 'out' direction on the interface the traffic will leave (or any interface) with the same source/destination, and set the timeout there also.
Logged
Need help fast?
Commercial Support
!
Co-Author of
pfSense: The Definitive Guide
. - Check the
Doc Wiki
for FAQs.
Do not PM for help!
Donate to the project
|
My Wish List
theflakes
Newbie
Offline
Posts: 17
Re: rule state timeout
«
Reply #3 on:
July 08, 2012, 05:50:32 pm »
Thanks
Unfortunately it breaks any connection. The following is what I defined on the floating rule:
pass:apply immediately:tcp:same source: same dest(any):300 timeout for state
With the above rule active tcp connection never reach established:established. I tried multiple variations on this rule with no success.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Administrative
-----------------------------
=> Forum rules
=> Messages from the pfSense Team
=> Feedback
-----------------------------
pfSense English Support
-----------------------------
=> Installation and Upgrades
=> General Questions
=> 2.1 Snapshot Feedback and Problems
=> Post a bounty
===> Completed Bounties
===> Expired/Withdrawn Bounties
=> Hardware
=> Firewalling
=> NAT
=> CARP/VIPs
=> Routing and Multi WAN
=> Traffic Shaping
=> DHCP and DNS
=> IPv6
=> IPsec
=> PPTP
=> PPPoE Server
=> Captive Portal
=> webGUI
=> Wireless
=> SNMP
=> Packages
=> Virtualization installations and techniques
=> OpenVPN
=> Gaming
-----------------------------
Development/Documentation
-----------------------------
=> Documentation
=> Development
-----------------------------
General Category
-----------------------------
=> General Discussion
-----------------------------
International Support
-----------------------------
=> Indonesian
=> Deutsch
=> Español
=> Français
=> Italiano
=> Russian
=> Nederlands
=> Norwegian
=> Portuguese
=> Polish
=> Romanian
=> Swedish
=> Turkish
-----------------------------
Retired
-----------------------------
=> 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
=> 1.2.1-RC Snapshot Feedback and Problems-RETIRED
=> 2.0-RC Snapshot Feedback and Problems - RETIRED
=> DNS Server testing area - RETIRED
Loading...