Re: Firewall rules order and performance
"Marcus J. Ranum" <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
[email protected] wrote: the number of already > established connections in the kernel was the primary factor. You'd plateau > after a certain point as new connections were trying to allocate the memory. I never understood why anyone would have a problem with that. Just pre-allocate a pool and (if you're really into it) marshall your pools based on the hash function you use to match the streams so that stream data related to a particular hash chain tend to be in the same memory pages. It always seemed to me that a lot of the "system design" of firewalls was "let's put our head between our knees and hope Moore's law or marketing takes care of it for us." mjr. -- Marcus J. Ranum CSO, Tenable Network Security, Inc. http://www.tenablesecurity.com