Re: Huge impact of the conntrack mechanism on routing performance (30% with a single conntrack entry)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



From: Eddy Kvetny <eddy_kvetny@xxxxxxxxx>
Date: Wed, 5 Apr 2006 07:03:05 -0700 (PDT)

> Right after "insmod ip_conntrack.ko" the throughput
> drastically falls to 28 kpps (-12 kpps or -30% !!!).

Yes, this is pretty much what the cost of netfilter is for a router.

This has been known and well understood for a long time, and solutions
to this problem are not easy which is why there hasn't been any
progress in this area to date.


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux