Browse Source

add src.track timeout and src-nodes limit

ok mcbride@
OPENBSD_3_5
david 21 years ago
parent
commit
fda326318f
1 changed files with 3 additions and 3 deletions
  1. +3
    -3
      src/etc/pf.conf

+ 3
- 3
src/etc/pf.conf View File

@ -1,4 +1,4 @@
# $OpenBSD: pf.conf,v 1.25 2004/01/29 18:54:29 todd Exp $
# $OpenBSD: pf.conf,v 1.26 2004/02/26 22:11:11 david Exp $
# #
# See pf.conf(5) and /usr/share/pf for syntax and examples. # See pf.conf(5) and /usr/share/pf for syntax and examples.
# Required order: options, normalization, queueing, translation, filtering. # Required order: options, normalization, queueing, translation, filtering.
@ -15,14 +15,14 @@
#table <foo> { 10.0.0.0/8, !10.1.0.0/16, 192.168.0.0/24, 192.168.1.18 } #table <foo> { 10.0.0.0/8, !10.1.0.0/16, 192.168.0.0/24, 192.168.1.18 }
# Options: tune the behavior of pf, default values are given. # Options: tune the behavior of pf, default values are given.
#set timeout { interval 10, frag 30 }
#set timeout { interval 10, frag 30, src.track 0 }
#set timeout { tcp.first 120, tcp.opening 30, tcp.established 86400 } #set timeout { tcp.first 120, tcp.opening 30, tcp.established 86400 }
#set timeout { tcp.closing 900, tcp.finwait 45, tcp.closed 90 } #set timeout { tcp.closing 900, tcp.finwait 45, tcp.closed 90 }
#set timeout { udp.first 60, udp.single 30, udp.multiple 60 } #set timeout { udp.first 60, udp.single 30, udp.multiple 60 }
#set timeout { icmp.first 20, icmp.error 10 } #set timeout { icmp.first 20, icmp.error 10 }
#set timeout { other.first 60, other.single 30, other.multiple 60 } #set timeout { other.first 60, other.single 30, other.multiple 60 }
#set timeout { adaptive.start 0, adaptive.end 0 } #set timeout { adaptive.start 0, adaptive.end 0 }
#set limit { states 10000, frags 5000 }
#set limit { states 10000, src-nodes 10000, frags 5000 }
#set loginterface none #set loginterface none
#set optimization normal #set optimization normal
#set block-policy drop #set block-policy drop


Loading…
Cancel
Save