All of lore.kernel.org
 help / color / mirror / Atom feed
From: don-nf@isis.cs3-inc.com (Don Cohen)
To: netfilter-devel@lists.samba.org
Subject: Re: performance issues (nat / conntrack)
Date: Sun, 23 Jun 2002 21:46:29 -0700	[thread overview]
Message-ID: <15638.42021.31206.821255@isis.cs3-inc.com> (raw)
In-Reply-To: <20020623132739.12D52455E@lists.samba.org>

 > From: "Jean-Michel Hemstedt" <jean-michel.hemstedt@alcatel.be>
 > >  > Since in my test, each connection is ephemeral (<10ms) ...

One question here is whether the traffic generator is acting like
a real set of users or like an attacker.  A real user would not keep
trying to make connections at the same rate if the previous attempts 
were not being served.  I suspect you're acting more like an attacker.

 > > So I'm guessing that large number of entries in conntrack table is
 > > evidence that packets are being lost.  
 > not only: a crashed endpoint breaking the tcp sequence causes also
 > garbage entries in conntrack (known issue).
Again, a crashed endpoint would likely not get as many hits.
My guess is that the reason for all the conntrack entries is related
to what I described in my earlier mail.  Creating conntrack entries is
expensive.  My machine could only do it about 1000 time/sec.  Off hand
I don't know which packets are dropped.  I'd guess that the ones that
make it through the conntrack code do get forwarded, but I don't know.
If, for example, the return packets are lost because we're too busy 
adding new conntrack entries, then there's nothing to cause the
entries to go away, other than those timeouts.

 > > Just wondering, how did you measure cpu load?
 > procinfo -n10 ; [d] for showing differences, which in fact, computes
 >                    the differences of cumulated cpu time (got from 
 >                    /proc/stat) on the given period: (tsys1-tsys0)/T
I see /proc/stat - user, nice, system, idle.  Thank you.  Very useful.

================

 > > Everybody agrees that NAT is evil and it should be avoided in all
 > circumstances.
This is news to me!  Is this just because the implementation is
lacking or some more fundamental reason?

       reply	other threads:[~2002-06-24  4:46 UTC|newest]

Thread overview: 46+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20020623132739.12D52455E@lists.samba.org>
2002-06-24  4:46 ` Don Cohen [this message]
2002-06-24  6:06   ` performance issues (nat / conntrack) Patrick Schaaf
     [not found]     ` <15638.48245.84830.480715@isis.cs3-inc.com>
2002-06-24  6:48       ` Patrick Schaaf
2002-06-24  6:54         ` Don Cohen
2002-06-24  7:13           ` Patrick Schaaf
2002-06-24 15:18             ` Don Cohen
2002-06-25  2:44               ` Harald Welte
     [not found] <20020625151007.980D14140@lists.samba.org>
2002-06-25 17:00 ` Don Cohen
2002-06-25 21:47   ` Jean-Michel Hemstedt
2002-06-26 14:50     ` Harald Welte
2002-06-26 18:04       ` Jean-Michel Hemstedt
     [not found] <20020621132640.2C326472B@lists.samba.org>
2002-06-21 17:35 ` Don Cohen
2002-06-21 18:26   ` Jean-Michel Hemstedt
2002-06-23  9:14   ` Jean-Michel Hemstedt
2002-06-25 10:38     ` Jozsef Kadlecsik
2002-06-25 11:11       ` Jean-Michel Hemstedt
2002-06-25 11:48         ` Jozsef Kadlecsik
2002-06-20 19:48 Jean-Michel Hemstedt
2002-06-22 16:51 ` Harald Welte
2002-06-23  9:15   ` Jean-Michel Hemstedt
2002-06-25 11:33     ` Jozsef Kadlecsik
2002-06-25 12:47       ` Harald Welte
2002-06-25 14:23         ` Jozsef Kadlecsik
     [not found]         ` <025001c21c50$763fa880$0489cb8a@etbx180>
2002-06-25 16:07           ` Harald Welte
2002-06-25 21:08         ` Jozsef Kadlecsik
2002-06-25 13:21       ` Jean-Michel Hemstedt
2002-06-25 13:51         ` Harald Welte
2002-06-25 14:33           ` Jozsef Kadlecsik
2002-06-25 14:51           ` Jean-Michel Hemstedt
2002-06-25 16:11             ` Harald Welte
2002-06-25 13:52         ` Patrick Schaaf
2002-06-25 14:53         ` Jozsef Kadlecsik
2002-06-25 15:22           ` Balazs Scheidler
2002-06-25 10:35 ` Jozsef Kadlecsik
2002-06-25 12:42   ` Jean-Michel Hemstedt
2002-06-25 13:50     ` Patrick Schaaf
2002-06-25 19:03       ` Harald Welte
2002-06-25 13:56     ` Alex Bennee
2002-06-25 14:17     ` Jozsef Kadlecsik
2002-06-25 15:13       ` Balazs Scheidler
2002-06-25 19:06         ` Harald Welte
2002-06-26  8:18           ` Balazs Scheidler
2002-06-27  2:21       ` Andrew Smith
2002-06-27 11:24         ` Harald Welte
2002-06-29  5:25           ` Andrew Smith
2002-06-25 19:01     ` Harald Welte

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=15638.42021.31206.821255@isis.cs3-inc.com \
    --to=don-nf@isis.cs3-inc.com \
    --cc=netfilter-devel@lists.samba.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.