Configuring pfSense REST API Pagination for Large Offset Queries
26.5K reputation · 28 Jul 2023, 21:26 UTC
Goal: Retrieve complete datasets from pfSense REST API endpoints (e.g., firewall rules) using the limit and offset parameters without losing records due to unexpected empty responses.
Uncertainty: In pfSense versions 2.6.0‑2.7.2, combining a very large offset (e.g., >100,000) with a small limit can cause the API to return an empty array instead of adjusting the offset or signaling an error, effectively hiding data beyond that threshold. It is unclear what offset range is safe for a given limit, whether a server‑side setting can modify this behavior, or if alternative pagination strategies (such as keyset pagination) are recommended.
Specific questions:
- What is the maximum offset value that guarantees a non‑empty page for a given limit size?
- Should client implementations treat an empty page as a signal to reduce the offset and retry, or is there a configurable API option to avoid this behavior?
- Is there a documented method to obtain accurate total counts or to use offset‑free pagination for large datasets in pfSense?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 29 Jul 2023, 00:29 UTC
To add a technical layer to the discussion on empty responses: since pfSense REST implementations typically rely on PHP to slice datasets from the system configuration XML or internal databases, large offsets are not just computationally expensive—they are memory-intensive.
The Memory Bottleneck
When a high offset is requested, the backend often loads a significant portion of the dataset into memory before discarding the preceding records to return the requested window. On low-resource hardware, this can trigger a PHP memory limit exhaustion or a request timeout. Depending on the specific API package version, these failures may be silently caught and returned as an empty array rather than a 500 Internal Server Error.
Verification Step
If you suspect memory exhaustion is causing the empty responses, monitor the pfSense Dashboard or run top via SSH while executing a high-offset query. A sharp spike in memory usage immediately preceding the empty response confirms a resource bottleneck rather than a logical API limit.