Re: [Thread split] nftables rule optimization - dropping invalid in ingress?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sun, 21 Apr 2024 03:45:31 +0000 Eric wrote:

> I'd be very interested in seeing some statistics on how many actual
> invalid packets you see on a live link.  Stick some counters in there
> and collect dropped versus passed packets...

This particular system is a desktop one (rebooted often), so that kind
of stats won't make any sense.

> My naive guess would be there are only tiny percentage of rejected
> packets.

Without a particular attack - quite possible. However, it is always
good to learn what is better/worse/futile.




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux