Re: Recommended hardware for iptables based firewall/router

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Dennis Jacobfeuerborn <dennisml@xxxxxxxxxxxx>

The EdgeRouter 's asic couldn't handle all use cases ,  Having some
special rule will make it go to "offload" disabled mode.  You should
research if that's the problem.

As for Linux as a router, the key thing you want to test for is PPS,
not BPS.  Commodity hardware should be able to handle up to 1Mpps. Buy
the best Xeon within your budget. Don't bother look at anything else.
(if your project is serious and need to survive a ddos attack)

Cheers.

On Sat, Nov 8, 2014 at 4:48 PM, Yucong Sun <sunyucong@xxxxxxxxx> wrote:
>
> The EdgeRouter 's asic couldn't handle all use cases , Having some special
> rule will make it go to "offload" disabled mode.
>
> You should research if that's the problem.
>
> As for Linux as a router, the key thing you want to test for is PPS, not
> BPS. Commodity hardware should be able to handle up to 1Mpps. Buy the best
> Xeon within your budget. Don't bother look at anything else. (if your
> project is serious and need to survive a ddos attack)
>
> Cheers
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux