Matt Zagrabelny a écrit :
Okay, I see now. Performance would be related to the number of rules that each packet needs to be tested against not against the criterion of the match.
One suggestion : if performance happens to be an issue, it might be worth using ipset and the 'set' match instead of the 'mac' match.
- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html