[nftables] economics of reverse path filtering - FIB expression vs. kernel parameter

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Presumably NFT rule

* filter prerouting fib saddr . iif oif missing drop

and kernel parameter

net.ipv4.conf.<interface>.rp_filter = 2

achieving the same goal.

Which one comes into effect first, if there is difference assuming that both are being processed through netfilter? Is one or the other more economic with regard to CPU cycles and/or responsiveness?






[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux