All of lore.kernel.org
 help / color / mirror / Atom feed
* netfilter under heavy load.
@ 2003-01-05 15:40 Mike Olivere
  2003-01-06 11:24 ` ITM CS Ruslan O. Nesterov
  0 siblings, 1 reply; 3+ messages in thread
From: Mike Olivere @ 2003-01-05 15:40 UTC (permalink / raw)
  To: netfilter

Hello, I don't know if this has been brought up before but I am going to be
running netfilter under load on a fractional T-3 (12Mbps). The box will have
3 interfaces eth0 going to the Cisco 7200, eth1 (routable IPs) going to the
webfarm for DMZ zone, and then eth2 will be NATed with a private LAN IP
(192.168.1.x). I will be NATing over 200 clients and I know in the past this
could be a problem with IPCHAINS because it would either run out of memory
or start dropping connections. The webservers get about 7,000 hits a day and
they won't be NATed but will be filtered with a mix of statefule and packet
filtering rules. We have a Cisco PIX 525(which is just a Intel P600/512MB
RAM) in place right now but I would like to move to Netfilter as it will be
running on a dual P1ghz and a gig of memory. Is this possible? can Nefilter
scale to this and beyond? and is there any tweaks I should know about?

Thanks in advance.

Mike



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2003-01-06 23:08 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-01-05 15:40 netfilter under heavy load Mike Olivere
2003-01-06 11:24 ` ITM CS Ruslan O. Nesterov
2003-01-06 23:08   ` Chris Straessle

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.