Re: Is this firewall good enough?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wed, 9 Jun 2004, Feizhou wrote:

> > Is there any good reason not to load connection tracking?
>
> SLOW. It isn't good enough to use on a high traffic server.

Could you back your claims up with data?

At testing connection tracking we could pump trough two million concurrent
connection at 200000pps rate with opening up 20000 new connection per
second on a dual Xeon PC with Serverworks chipset and Intel copper GE
cards. Best results were achieved by Linux kernel 2.6.x with conntrack
locking and TCP window tracking patches applied and NAPI enabled.
I'd say that's not bad at all.

Best regards,
Jozsef
-
E-mail  : kadlec@xxxxxxxxxxxxxxxxx, kadlec@xxxxxxxxxxxxxxx
PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
Address : KFKI Research Institute for Particle and Nuclear Physics
          H-1525 Budapest 114, POB. 49, Hungary



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux