Re: kernel option "Bridged IP/ARP packets filtering" degrades bridging performance
Bart De Schuymer <[email protected]>
| Newsgroups | gmane.linux.network.bridge.ebtables.devel |
|---|---|
| Message-ID | <[email protected]> |
Op wo, 31-08-2005 te 16:07 +0900, schreef Cho-Soon Yim: > Hi, > > I have tested the bridging performance of Linux. > Linux machine; > Xeon 3.06GHz * 2 CPU > 1 G Memory(DDR266 ECC) > intel e1000 NIC 2 port LC type * 1 driver version( 64bit/133Mhz with > riser card) > > But when I enabled that option(I recompiled the kernel), I got success > rate 5%. > It was a half of prior result. > I did not add any filter rules. I just enabled that option because I > wanted to use bridge firewalling. > > I have tried to tune the kernel, network kernel paramenters, and NIC > drivers. > But anything could not compensate the performance degration that was > caused by bridging packet filter option. > Is there anyone who addressed this issue out there? > I'd like to know the experience of whom tested this kind of bridging > firewall. Are there no rules in iptables either? Is connection tracking enabled? There are not much details about performance. See e.g. http://sourceforge.net/mailarchive/forum.php?thread_id=2625911&forum_id=8573 cheers, Bart ------------------------------------------------------- SF.Net email is Sponsored by the Better Software Conference & EXPO September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf