HP-UX IPFilter A.03.05.13 Administrator's Guide: HP-UX 11i v3

Table Of Contents
Installing and Configuring HP-UX IPFilter
Kernel Tunable Parameters
Chapter 1 15
The default timeout value is 86,400 seconds. The minimum value that
can be set for fr_tcpidletimeout is 300 seconds.
For information on changing the fr_tcpidletimeout variable, see
“Configuring Kernel Tunable Parameters” on page 17.
fr_statemax
The purpose of the fr_statemax variable is to restrict how many entries
can be created. Configure the values of this variable appropriately for
your environment.
The following table displays the default, minimum and maximum values
for fr_statemax. HP recommends not setting the value for each tunable
below the stated minimum value or above the stated maximum value.
For information on changing the fr_statemax variable using kctune,
see “Configuring Kernel Tunable Parameters” on page 17.
Memory is allocated for state and limit entries in chunks. For state
entries, memory is allocated by increments of 1,300 entries. The
approximate size of the state is 384 bytes. HP-UX IPFilter keeps the
allocated memory for state entries in its private free pool.
IMPORTANT The state values should not be set too high because the memory
allocations are not released back to the kernel memory pool for general
use.
Tunable Name
Default
Value
Minimum
Value
Maximum
Value
fr_tcpidletimeout 86,400
seconds
240 seconds 86,400
seconds
Tunable
Name
Default Value
Minimum
Value
Maximum Value
fr_statemax 800,000 entries 4,000 entries 1,600,000 entries