Limits?
Wim Kerkhoff <[email protected]>
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
Hi everyone, I'm working on configuring a bridge for our network, which will permit frames for only a set number of IP/MAC pairs to pass through. Traffic from any other IP/MAC will be restricted to a 10.0.0.0/8 address space (assigned via DHCP) and redirected to a login web page. The bridge members will be about ten source 802.1q VLAN interfaces connected via one gig interface, outputing to another gig interface to a Layer 3 switch. For frames coming from the the L3 switch, the bridge will need to figure out which of the 10 VLANs that the destination MAC is on. Each VLAN interface has about 1000 MACs on them, in various assorted subnets. Systems with addresses in the same subnet can be found on any of the VLANs. But, only IPs in different subnets need to be able to communicate with each other. So, some ebtables rules on the bridge will force all frames up to a Layer 3 router (via the 2nd NIC) for routing. Everything I've read about ebtables indicates this will be possible. Hardware is a 1U server, Intel 2.8+ Ghz, 512 MB, SATA RAID1, dual gig copper interfaces. Software is Debian Sarge, Kernel 2.6.11 (or latest available). Just wanted to do a sanity check -- am I out to lunch on this? Will the large number of rules slow down the effective throughput? I'm trying to design for minimal latency (<1-2 ms) and maximum throughput (300+ mbit/s) while preventing nasty ARP storms, IP spoofing/hijacking, etc. Wim ------------------------------------------------------- This SF.Net email is sponsored by: NEC IT Guy Games. How far can you shotput a projector? How fast can you ride your desk chair down the office luge track? If you want to score the big prize, get to know the little guy. Play to win an NEC 61" plasma display: http://www.necitguy.com/?r=20