Re: Limits?

Wim Kerkhoff <[email protected]>
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
Bart De Schuymer wrote:

>Op ma, 13-06-2005 te 19:38 -0700, schreef Wim Kerkhoff:
>  
>
>>Will the large number of rules slow down the effective throughput? I'm 
>>trying to design for minimal latency (<1-2 ms) and maximum throughput 
>>(300+ mbit/s) while preventing nasty ARP storms, IP spoofing/hijacking, etc.
>>    
>>
>
>You can minimize the number of rules by using the among match. The more
>rules you have, the lower the throughput will be. A well-designed rule
>set can improve your throughput a lot.
>
So a single "among" rule with 5000 matches should be fine, and much 
faster then seperate rules... nice. Running many rules (iptables or 
ebtables) in a linear fasion always seems really inefficient to do on a 
packet by packet basis.

I guess I won't know for sure how well the "thousands of rules" bridging 
scenario works out until running it under a packet generator or in a 
production environment.

Thanks for the reply,

Wim



-------------------------------------------------------
This SF.Net email is sponsored by: NEC IT Guy Games.  How far can you shotput
a projector? How fast can you ride your desk chair down the office luge track?
If you want to score the big prize, get to know the little guy.  
Play to win an NEC 61" plasma display: http://www.necitguy.com/?r=20
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.