2 ms·
Running out of state table space is a very common issue for firewalls subjected to a DoS or other unprecedented high traffic situation. The only thing OpenBSD-s
by PreInternet01 3y ago
Running out of state table space is a very common issue for firewalls subjected to a DoS or other unprecedented high traffic situation. The only thing OpenBSD-specific here is probably the very conservative default table size.
For DNS servers that are set up with rate limits, keeping state on the firewall is pointless, so it's probably best to skip that (on OpenBSD: `pass no state`, I think) -- the destination server itself knows best what's abusive traffic and what's not, so on the firewall, do nothing except count the packets...