Re: Limits?
Carl-Daniel Hailfinger <[email protected]>
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
Wim Kerkhoff schrieb: > Bart De Schuymer wrote: > >> Op ma, 13-06-2005 te 19:38 -0700, schreef Wim Kerkhoff: >> >> >>> Will the large number of rules slow down the effective throughput? >>> I'm trying to design for minimal latency (<1-2 ms) and maximum >>> throughput (300+ mbit/s) while preventing nasty ARP storms, IP >>> spoofing/hijacking, etc. >>> >> >> >> You can minimize the number of rules by using the among match. The more >> rules you have, the lower the throughput will be. A well-designed rule >> set can improve your throughput a lot. >> > So a single "among" rule with 5000 matches should be fine, and much > faster then seperate rules... nice. Running many rules (iptables or > ebtables) in a linear fasion always seems really inefficient to do on a > packet by packet basis. The "among" match doesn't work on 64 bit. I tried to debug it, but lack of time prevented me from fixing it. Perhaps I'll try to get it running under UML (the machine is already in production). Regards, Carl-Daniel -- http://www.hailfinger.org/ ------------------------------------------------------- This SF.Net email is sponsored by: NEC IT Guy Games. How far can you shotput a projector? How fast can you ride your desk chair down the office luge track? If you want to score the big prize, get to know the little guy. Play to win an NEC 61" plasma display: http://www.necitguy.com/?r=20