Re: Simple PF Router/Firewall/NAT requirements: was Performance optimizing OpenBSD 7.2

2023-02-15 Thread patric conant
no On Wed, Feb 15, 2023 at 10:21 PM Steve Litt wrote: > Claudio Jeker said on Wed, 15 Feb 2023 14:14:11 +0100 > > > >I think the state-mismatch is a result of hitting the state limit and > >not the other way around. At over 90'000 states the default timeouts > >are reduced by more than 50% and

Simple PF Router/Firewall/NAT requirements: was Performance optimizing OpenBSD 7.2

2023-02-15 Thread Steve Litt
Claudio Jeker said on Wed, 15 Feb 2023 14:14:11 +0100 >I think the state-mismatch is a result of hitting the state limit and >not the other way around. At over 90'000 states the default timeouts >are reduced by more than 50% and so states are removed too soon >resulting in a state-mismatch. >