Re: New rule impact

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



With the string match you can not be sure that the string that you want
compares is encapsulated in a single packet, then that mechanics does
not work well if you want block some URLs.

I don't know what you want but if you want block http traffic maybe is
better for you squid.

Hope this help.

Jorge. 

El mié, 03-05-2006 a las 14:46 -0300, Filipe Mordhorst escribió:
> Hello everyone,
> 
> I was searching the net (including google) for the best way to take a
> measurement for additional processor requirement and additional overhead
> when adding a specific rule.
> The fact is that I’m starting to work with the string match. A already know
> how to implement it, but I need to know how it will affect my environment.
> 
> Thanks for now
> 
> Best regards,
> ----
> Filipe Mordhorst  
> Brasil - SC
> 
-- 
Jorge Isaac Davila Lopez
Nicaragua Open Source
+505 808 2478
davila@xxxxxxxxxxxxxxxxxxxxxxx 



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux