pf live response time to table additions

I have a table used to block abusive IPs from accessing my server, but there seems to be a delay of a minute or so after the table is updated with pfctl -t tablename -T add before incoming packets get dropped. Is there a way to shorten the response time and what is the downside of doing so?
 
It's probably not a delay in processing of the table, but you need to remember there might be active states in the firewall that are allowing an existing session to continue (keep state). A block rule only applies to new connection attempts (for TCP that would be the first SYN packet).
 
How are the entries getting added to the table? From within a pf rule or an external application?

And as usual,SirDice beat me to the second part :)
 
I have now added a pfctl -k $BAD_IP_ADDRESS to my script. Let's see whether that helps.

The script has already reduced abusive activity quite a lot and the server seems snappier at responding to requests as a result. The error logs are shrinking noticeably!
 
  • Like
Reactions: mer
Back
Top