Re: Firewall rules order and performance

"Marcus J. Ranum" <[email protected]>
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
[email protected] wrote:
the number of already
> established connections in the kernel was the primary factor. You'd plateau
> after a certain point as new connections were trying to allocate the memory.

I never understood why anyone would have a problem with that.
Just pre-allocate a pool and (if you're really into it) marshall
your pools based on the hash function you use to match
the streams so that stream data related to a particular
hash chain tend to be in the same memory pages.

It always seemed to me that a lot of the "system design"
of firewalls was "let's put our head between our knees and
hope Moore's law or marketing takes care of it for us."

mjr.
-- 
Marcus J. Ranum		CSO, Tenable Network Security, Inc.
			http://www.tenablesecurity.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.