Re: Dropped inbound packets from stateful allow rule
"Paul B. Henson" <[email protected]> Thu, 15 Apr 2010 14:32:27 -0700 (PDT)
| Newsgroups | gmane.comp.security.firewalls.ipfilter |
|---|---|
| Message-ID | <29050_1271367210_4BC78629_29050_6151_1_Pine.GSO.4.55.1004151428510.28895@loogie.intranet.csupomona.edu> |
On Thu, 15 Apr 2010, Darren Reed wrote:
> # ipfstat -slvdR | awk '/bkt/{print $11;}' - | sort -n | uniq -c | sort -n
I updated my logger script to include the 5 buckets with the most entries.
For the most recent 3 lost states, the most filled bucket only had 2 states
in it 8-/.
fr_state_maxbucket appears to be set to 34, so it doesn't seem the bucket
was full.
04/15/10-13:52 297 in use lost 1537 1 986, 1 99091, 1 9916, 1 99273, 1 99350,
04/15/10-13:53 292 in use lost 1538 1 9916, 1 9917, 1 99273, 1 99350, 2 68881,
04/15/10-14:14 368 in use lost 1538 1 99034, 1 99350, 1 99576, 1 99822, 1 99904,
04/15/10-14:15 367 in use lost 1539 1 99034, 1 99350, 1 99576, 1 99904, 2 85892,
04/15/10-14:23 277 in use lost 1539 1 97264, 1 97523, 1 98845, 1 99350, 2 86098,
04/15/10-14:24 271 in use lost 1540 1 98015, 1 98713, 1 98845, 1 99198, 1 99350,
--
Paul B. Henson | (909) 979-6361 | http://www.csupomona.edu/~henson/
Operating Systems and Network Analyst | [email protected]
California State Polytechnic University | Pomona CA 91768