Re: Synfloods - SNAT slow down

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> I have two thousand hosts and two thousand forward rules :(

With so many hosts/rules you should be able to match subnets instead of
each host separately, reducing the number of rules greatly which in turn
improves Netfilter performance. Or do you have a special reason to do
this ?


Gr,
Rob



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux