OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: OpenBSD 4.6 + carp + pf + pfsync lockup

From: Stuart Henderson (stuspacehopper.org)
Date: Thu Sep 09 2010 - 17:43:58 CDT


On 2010-09-09, Martin Pelik??n <martin.pelikangmail.com> wrote:
> 2010/9/9, Joe Warren-Meeks <joe.warren.meeksgmail.com>:
>> recv/send:
>> net.inet.tcp.recvspace=16384
>> net.inet.udp.recvspace=41600
>> joef1:/home/joe> sysctl -a |grep send
>> net.inet.tcp.sendspace=16384
>> net.inet.udp.sendspace=9216
>>
>>
>> Too low? What is a good value for them?
>
> It depends on what do you need. The defaults suffice for most cases,
> but on our most loaded router we use tcp both 256k and udp send space
> 65k (lots of dns). Just test it somewhere.

these affect traffic sourced from the box itself, *not* routed through it.