All of lore.kernel.org
 help / color / mirror / Atom feed
* Iptables 1.3.1 still not very fast.
@ 2005-04-01 20:47 Robert de Bath
  0 siblings, 0 replies; 11+ messages in thread
From: Robert de Bath @ 2005-04-01 20:47 UTC (permalink / raw)
  To: netfilter-devel

Okay, I'll admit is it a LOT faster that 1.2.11 it still seems to take a 
long time with big tables.

An example:
I have a program (I've called iptrange) that will take a file full of ip 
address ranges (192.168.42.10 192.168.42.25) and converts them into a set
of iptables chains that invokes another chain if the source (or dest) 
matches ie:

iptables -N CHECK
iptables -A CHECK -s 192.168.42.10/31 -j FOUND
iptables -A CHECK -s 192.168.42.12/30 -j FOUND
iptables -A CHECK -s 192.168.42.16/29 -j FOUND
iptables -A CHECK -s 192.168.42.24/31 -j FOUND

The good bit is that it will create a tree of subchains so that the
matching is efficient for large numbers of ip addresses.

This works well for a few hundred address ranges; I use it to match
recent 'evil' ips and ranges from dshield.org.

However, when I tried a 50000 range list from http://blocklist.org I
ran into problems.  After conversion it created 20000 chains with a
total of 70000 rules.  This tables took about an hour to load using
iptables-1.2.11!

Version 1.3.1 of libiptc is a LOT faster at about 5 minutes to do the
load. But this still seems very slow when it takes about half a second
to generate and print out the iptables rules to a script.

I hate to think how slow it would be with a million ranges; assuming 
it can be loaded it looks like it would be about 300000 chains, 1.3M
rules and about 100 rules checked per packet (to pick some figures out
of a single test) so it should be useable ...

BTW: iptables-restore is slower than my iptrange!

My problem is that I think that libiptc looks evil and I really don't
want to dive into messing with that code. So how can I help to make
libiptc run as fast as I'd like it to?

-- 
Rob.                          (Robert de Bath <robert$ @ debath.co.uk>)

^ permalink raw reply	[flat|nested] 11+ messages in thread
* Iptables 1.3.1 still not very fast.
@ 2005-04-01 21:52 Robert de Bath
  2005-04-02  4:53 ` Wang Jian
                   ` (2 more replies)
  0 siblings, 3 replies; 11+ messages in thread
From: Robert de Bath @ 2005-04-01 21:52 UTC (permalink / raw)
  To: netfilter-devel

Okay, I'll admit is it a LOT faster that 1.2.11 it still seems to take a long 
time with big tables.

An example:
I have a program (I've called iptrange) that will take a file full of ip 
address ranges (192.168.42.10 192.168.42.25) and converts them into a set
of iptables chains that invokes another chain if the source (or dest) matches 
ie:

iptables -N CHECK
iptables -A CHECK -s 192.168.42.10/31 -j FOUND
iptables -A CHECK -s 192.168.42.12/30 -j FOUND
iptables -A CHECK -s 192.168.42.16/29 -j FOUND
iptables -A CHECK -s 192.168.42.24/31 -j FOUND

The good bit is that it will create a tree of subchains so that the
matching is efficient for large numbers of ip addresses.

This works well for a few hundred address ranges; I use it to match
recent 'evil' ips and ranges from dshield.org.

However, when I tried a 50000 range list from http://blocklist.org I
ran into problems.  After conversion it created 20000 chains with a
total of 70000 rules.  This tables took about an hour to load using
iptables-1.2.11!

Version 1.3.1 of libiptc is a LOT faster at about 5 minutes to do the
load. But this still seems very slow when it takes about half a second
to generate and print out the iptables rules to a script.

I hate to think how slow it would be with a million ranges; assuming it can be 
loaded it looks like it would be about 300000 chains, 1.3M
rules and about 100 rules checked per packet (to pick some figures out
of a single test) so it should be useable ...

BTW: iptables-restore is slower than my iptrange!

My problem is that I think that libiptc looks evil and I really don't
want to dive into messing with that code. So how can I help to make
libiptc run as fast as I'd like it to?

-- 
Rob.                          (Robert de Bath <robert$ @ debath.co.uk>)

^ permalink raw reply	[flat|nested] 11+ messages in thread
* Re: Iptables 1.3.1 still not very fast
@ 2005-04-03  5:44 Robert Iakobashvili
  0 siblings, 0 replies; 11+ messages in thread
From: Robert Iakobashvili @ 2005-04-03  5:44 UTC (permalink / raw)
  To: netfilter-devel

 Gentlemen,

My suggestion for you is to look at the great ipset
Facility developed by Jozsef Kadlecsik and based on ippool 
by Joakim Axelsson, Patrick Schaaf and Martin Josefssonץ

http://people.netfilter.org/kadlec/ipset/

It works great.

Sincerely,
Robert Iakobashvili
roberti at gonetworks dot com

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2005-04-28 10:36 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-04-01 20:47 Iptables 1.3.1 still not very fast Robert de Bath
  -- strict thread matches above, loose matches on Subject: below --
2005-04-01 21:52 Robert de Bath
2005-04-02  4:53 ` Wang Jian
2005-04-02  5:32   ` Peter Enderborg
2005-04-02  5:41     ` Patrick Schaaf
2005-04-02  9:27   ` Robert de Bath
2005-04-03 21:11     ` Henrik Nordstrom
2005-04-02  9:10 ` Henrik Nordstrom
2005-04-02 10:11   ` Robert de Bath
2005-04-28 10:36 ` Harald Welte
2005-04-03  5:44 Robert Iakobashvili

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.