kernel option "Bridged IP/ARP packets filtering" degrades bridging performance
"Cho-Soon Yim" <csyimkor-/E1597aS9LT7Za/[email protected]>
| Newsgroups | gmane.linux.network.bridge.ebtables.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi,
I have tested the bridging performance of Linux.
Linux machine;
Xeon 3.06GHz * 2 CPU
1 G Memory(DDR266 ECC)
intel e1000 NIC 2 port LC type * 1 driver version( 64bit/133Mhz with riser
card)
But when I enabled that option(I recompiled the kernel), I got success rate
5%.
It was a half of prior result.
I did not add any filter rules. I just enabled that option because I wanted
to use bridge firewalling.
I have tried to tune the kernel, network kernel paramenters, and NIC
drivers.
But anything could not compensate the performance degration that was caused
by bridging packet filter option.
Is there anyone who addressed this issue out there?
I'd like to know the experience of whom tested this kind of bridging
firewall.
Thanks,
Yimbo
"Top of the Security Solution"
ÀÓ ÃÊ ¼ø ´ëÇ¥ÀÌ»ç
Cho Soon Yim / Network Consultant
¼¿ï½Ã ±¸·Î±¸ ±¸·Î3µ¿ 197-33
E&Cº¥Ã³Å¸¿öºôµù 3Â÷ 609È£
Tel. 02) 6330-2501
Fax. 02) 6330-2504
Pcs. 019-9438-3978
E-mail : [email protected]
enclue.bmp
(image/bmp, 19.6 KB) - not displayed