Re: Limits?
Wim Kerkhoff <[email protected]>
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
Bart De Schuymer wrote: >Op ma, 13-06-2005 te 19:38 -0700, schreef Wim Kerkhoff: > > >>Will the large number of rules slow down the effective throughput? I'm >>trying to design for minimal latency (<1-2 ms) and maximum throughput >>(300+ mbit/s) while preventing nasty ARP storms, IP spoofing/hijacking, etc. >> >> > >You can minimize the number of rules by using the among match. The more >rules you have, the lower the throughput will be. A well-designed rule >set can improve your throughput a lot. > So a single "among" rule with 5000 matches should be fine, and much faster then seperate rules... nice. Running many rules (iptables or ebtables) in a linear fasion always seems really inefficient to do on a packet by packet basis. I guess I won't know for sure how well the "thousands of rules" bridging scenario works out until running it under a packet generator or in a production environment. Thanks for the reply, Wim ------------------------------------------------------- This SF.Net email is sponsored by: NEC IT Guy Games. How far can you shotput a projector? How fast can you ride your desk chair down the office luge track? If you want to score the big prize, get to know the little guy. Play to win an NEC 61" plasma display: http://www.necitguy.com/?r=20