On Thursday 15 May 2008 14:26, Jan Engelhardt wrote: > On Thursday 2008-05-15 11:21, Anton wrote: > > IPTABLES - but it's known that iptables insert/lookup > > is very slow on huge rulesets (atleat with iptables > > 1.3.x) and slowness progresses approximatelly > > exponentially on growth of rules number. > > > >Do I miss anything? > > You missed IPMARK from Xtables-addons which does the > marking in O(1) instead of O(n). Great! This partially solves problem with marking while used with shaper, but in global scope - iptables remains slow? -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html