Re: debugging kernel during packet drops

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wednesday 2010-03-24 18:04, Eric Dumazet wrote:

>Le mercredi 24 mars 2010 à 17:28 +0100, Jan Engelhardt a écrit :
>> On Wednesday 2010-03-24 17:21, Eric Dumazet wrote:
>> >dsthash_find() takes a lot of cpu, its a sign your hash table params
>> >might be suboptimal.
>> >
>> >Please send us "iptables -nvL" 
>> 
>> Consider using "iptables-save" instead, because -nvL is just
>> an abridged tabular display.
>
>Yes you are right, but as I was also interested by rules and numbers
>(packets/bytes) of matches, please Jorrit post :
>
>iptables-save
>iptables -nvL

The numbers you get with iptables-save -c.
There really is not anything that save does not output, after all, it's 
meant to store the exact state.
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Netfitler Users]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux