Firewall aliases #Loaded value

Started by keeka, Today at 05:52:26 PM

Previous topic - Next topic
Some aliases (network aliases as far as I can tell) show an unexpected #Loaded value.
e.g. I have a networks alias currently containing a single CIDR 82.132.128.0/17. This shows #Loaded=5. Gemini AI suggests the higher than expected #Loaded may be due to pf internal alias optimisation and that a corresponding breakdown (5 entries) would be visible under diagnostics. That doesn't seem to be the case. Diagnostics just shows the same single CIDR for that particular alias.

I don't see that behavior offhand, although I didn't check my larger aliases (e.g. bogons). So it seems unlikely to be a table optimization, as I have several aliases that contain subnets of others and are evaluated in the same ruleset.

The example alias I gave is referenced in a destination NAT rule, a corresponding (unlinked/manual) firewall rule, and also in another firewall rule. All configured on WAN interface only.