Besides not enough mbuf clusters, it also could be that pf is hitting the limit of the state tables. See http://www.packetmischief.ca/2011/02...e-table-limit/ for an example.
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
|