Re: [Thread split] nftables rule optimization - dropping invalid in ingress?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Dňa 21. apríla 2024 3:45:31 UTC používateľ Eric <evil.function@xxxxxxxxx> napísal:

>I'd be very interested in seeing some statistics on how many actual
>invalid packets you see on a live link.  Stick some counters in there
>and collect dropped versus passed packets...
>
>My naive guess would be there are only tiny percentage of rejected
>packets.

Your guess is not as naive, at least on my low traffic server i have ~70
drops (IPv4) in last 7 days. On my router it is ~370 drops in both, the
INPUT & FORWARD chains (iptables), in last ~100 days. That are
really tiny fractions of other drops, but many drops (by IP) happens
before INVALID rule.

regards


-- 
Slavko
https://www.slavino.sk/





[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux