All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jose Maria Lopez <jkerouac@eresmas.com>
To: "netfilter@lists.netfilter.org" <netfilter@lists.netfilter.org>
Subject: Re: tracking usage by mac address
Date: 31 Aug 2004 21:52:29 +0200	[thread overview]
Message-ID: <1093975858.9232.61.camel@nostromo.bgsecm.com> (raw)
In-Reply-To: <3063e504083013374bd2a909@mail.gmail.com>

El lun, 30 de 08 de 2004 a las 22:37, George Alexandru Dragoi escribió:
> Well, i don't know if you want to log EVERYTHING.
> Remember ip_conntrackworkson streams, so you can log only NEW packets.
> I have like 90 rules with -m mac like those i said before + several
> port forwarding, on a P2 450Mhz, 100mbit internet connections, used a
> lot, almoust all the time at 11MB/s at upload (exactly where those
> rules aremostly hitted), and top says the sys load is arround 40% at
> most when i have full bandwith in use, but i think it is not because
> of the netfilter, but the PCI usage. Traffic at 50% usually needs much
> less CPU, like 5-10%. I also have many other rules for SYN scan
> limiting, bandwith counting, and so on.
> 

Obviously our system it's useful for a not huge set of
rules, we use it for a per service basis, not per IP or MAC.
We have been using it with a big number of rules (services)
and it works like a charm, without slowing the system, but
if you have a lot of MACs our system can be surely a bad
idea.

-- 
Jose Maria Lopez Hernandez
Director Tecnico de bgSEC
jkerouac@bgsec.com
bgSEC Seguridad y Consultoria de Sistemas Informaticos
http://www.bgsec.com
ESPAÑA

The only people for me are the mad ones -- the ones who are mad to live,
mad to talk, mad to be saved, desirous of everything at the same time,
the ones who never yawn or say a commonplace thing, but burn, burn, burn
like fabulous yellow Roman candles.
                -- Jack Kerouac, "On the Road"



      parent reply	other threads:[~2004-08-31 19:52 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-08-30  2:42 tracking usage by mac address Henry Baxter
2004-08-30 10:17 ` Chris Brenton
2004-08-30 11:34 ` Torsten Luettgert
2004-08-30 13:12   ` George Alexandru Dragoi
2004-08-30 18:54 ` Jose Maria Lopez
2004-08-30 20:37   ` George Alexandru Dragoi
2004-08-31  0:34     ` Henry Baxter
2004-08-31 19:52       ` Jose Maria Lopez
2004-08-31 19:52     ` Jose Maria Lopez [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1093975858.9232.61.camel@nostromo.bgsecm.com \
    --to=jkerouac@eresmas.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.