All of lore.kernel.org
 help / color / mirror / Atom feed
* Rule matchup in iptables
@ 2003-03-06 12:47 Javier Miguel =?unknown-8bit?q?Rodr=EDguez?=
  2003-03-06 13:34 ` Athan
  2003-03-06 21:08 ` ...
  0 siblings, 2 replies; 3+ messages in thread
From: Javier Miguel =?unknown-8bit?q?Rodr=EDguez?= @ 2003-03-06 12:47 UTC (permalink / raw)
  To: netfilter


	Hello

	I have a iptables based firewall, with 5 gigabit ethernet
adapters and almost 8000 rules (ouch!). This is a "test bed", (still) not a
production enviroment

	I can see delays in traffic when crosses the firewall
(miliseconds). I want to optimize the firewall rules (we use a LOT of
VoIP) , so this is my question: Is there any way to know when a packet matches a rule? 
-j LOG is not feasible (thousands of packets per second). I want something like this: 

Last two hours:

Rule 1: 15000 hits, 150 megabytes
Rule 2: 3500 hits, 34 megabytes
Rule 3: 9675 hits, 2 megabytes
ad infinitum...

	Other question? How can I test iptables rules? In ipchains I
could try them, but with iptables do I have to generate fake traffic?

	Thank you for your support.



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2003-03-06 21:08 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-03-06 12:47 Rule matchup in iptables Javier Miguel =?unknown-8bit?q?Rodr=EDguez?=
2003-03-06 13:34 ` Athan
2003-03-06 21:08 ` ...

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.