From: "Filip Sneppe (Cronos)" <filip.sneppe@cronos.be>
To: netfilter@lists.samba.org
Subject: benchmark tool for netfilter - any recommendations ?
Date: 18 Jun 2002 14:11:22 +0200 [thread overview]
Message-ID: <1024402282.591.20.camel@xbox> (raw)
Hi,
I am looking for a traffic generator type aplication that can
generate a realistic workload to test a netfilter firewall.
There are some cool tools out there for throughput measurements,
like netpipe, etc. but they are not ideal to test connection
tracking performance. The way I see it, you either have tools
that:
- flood the network with traffic over just one TCP connection
or UDP stream. Not a lot of use in testing connection tracking
performance as it's just one ESTABLISHED connection.
or
- flood the network with more or less random crap as far as IP
addresses/ports is concerned. Not a very realistic workload
either.
IMHO a realistic workload for testing connection tracking
performance is a workload that has a limited number of IP
addresses on one side of the firewall (a DMZ with 64 hosts,
or a LAN with 100-500 hosts) and a wide range of IP addresses
at the other side (the Internet). The tool should be able
to mimic normal network behavior like short connections (http)
vs. longer lived connection (ftp download), etc.
It would be nice to have a client/server tool that you could be
used in this type of setup:
client ------ FW ------ server
and where either client and/or server could generate traffic
from various IP addresses/ports in a controlled way.
I am currently looking at Web-Polygraph (www.web-polygraph.org)
from the Squid developers, but upon installation, I realized
the license doesn't allow the publishing of the results.
Are there any tools worth looking at ? Is there anything else a
decent netfilter (firewall ?) performance benchmarking tool
should be able to do ?
Regards,
Filip
next reply other threads:[~2002-06-18 12:11 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-06-18 12:11 Filip Sneppe (Cronos) [this message]
2002-06-18 17:38 ` benchmark tool for netfilter - any recommendations ? Rodrigo Senra
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1024402282.591.20.camel@xbox \
--to=filip.sneppe@cronos.be \
--cc=netfilter@lists.samba.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.