On Wednesday 2010-03-24 18:04, Eric Dumazet wrote: >Le mercredi 24 mars 2010 à 17:28 +0100, Jan Engelhardt a écrit : >> On Wednesday 2010-03-24 17:21, Eric Dumazet wrote: >> >dsthash_find() takes a lot of cpu, its a sign your hash table params >> >might be suboptimal. >> > >> >Please send us "iptables -nvL" >> >> Consider using "iptables-save" instead, because -nvL is just >> an abridged tabular display. > >Yes you are right, but as I was also interested by rules and numbers >(packets/bytes) of matches, please Jorrit post : > >iptables-save >iptables -nvL The numbers you get with iptables-save -c. There really is not anything that save does not output, after all, it's meant to store the exact state. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html