Re: Limits?

Carl-Daniel Hailfinger <[email protected]>
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
Wim Kerkhoff schrieb:
> Bart De Schuymer wrote:
> 
>> Op ma, 13-06-2005 te 19:38 -0700, schreef Wim Kerkhoff:
>>  
>>
>>> Will the large number of rules slow down the effective throughput?
>>> I'm trying to design for minimal latency (<1-2 ms) and maximum
>>> throughput (300+ mbit/s) while preventing nasty ARP storms, IP
>>> spoofing/hijacking, etc.
>>>   
>>
>>
>> You can minimize the number of rules by using the among match. The more
>> rules you have, the lower the throughput will be. A well-designed rule
>> set can improve your throughput a lot.
>>
> So a single "among" rule with 5000 matches should be fine, and much
> faster then seperate rules... nice. Running many rules (iptables or
> ebtables) in a linear fasion always seems really inefficient to do on a
> packet by packet basis.

The "among" match doesn't work on 64 bit. I tried to debug it, but lack
of time prevented me from fixing it. Perhaps I'll try to get it running
under UML (the machine is already in production).

Regards,
Carl-Daniel
-- 
http://www.hailfinger.org/


-------------------------------------------------------
This SF.Net email is sponsored by: NEC IT Guy Games.  How far can you shotput
a projector? How fast can you ride your desk chair down the office luge track?
If you want to score the big prize, get to know the little guy.  
Play to win an NEC 61" plasma display: http://www.necitguy.com/?r=20
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.