All of lore.kernel.org
 help / color / mirror / Atom feed
* tc filtering vs iptables
@ 2004-08-27 13:46 jamal
  2004-08-27 15:54 ` Henrik Nordstrom
  0 siblings, 1 reply; 13+ messages in thread
From: jamal @ 2004-08-27 13:46 UTC (permalink / raw)
  To: Harald Welte; +Cc: netfilter-devel

Harald or anyone from the netfilter devel cabal: 

I am trying to do a performance comparison for basic stateless
firewalling using tc and iptables. I want to provide a fair analysis
but dont know how well to optimize iptables. I know you can use chains
but not sure what the best way to approach it in this case. I will
describe what i am trying to do in English and someone please help
provide it in iptables-speak:

I want to be able to have many hosts[1] accessing a web server at
TCP port 80. The return path is asymetric so wont go via same box.
In this case clearly the ephemeral src port will vary as will the src IP
but nothing else.
Anything that doesnt match gets dropped i.e thats the default rule.

Let me know how to create proper chains for a range of hosts
{1,2,8, 64,256,4096,8192,16384,32768,64K} 

cheers,
jamal

^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2004-08-28 11:19 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-08-27 13:46 tc filtering vs iptables jamal
2004-08-27 15:54 ` Henrik Nordstrom
2004-08-27 18:45   ` jamal
2004-08-27 20:11     ` Bill Rugolsky Jr.
2004-08-27 20:27       ` jamal
2004-08-27 20:42         ` KOVACS Krisztian
2004-08-27 21:03           ` jamal
2004-08-27 23:50         ` Henrik Nordstrom
2004-08-28  0:00         ` Henrik Nordstrom
2004-08-28  1:35           ` jamal
2004-08-28  7:08             ` Henrik Nordstrom
2004-08-28 11:19               ` jamal
     [not found]     ` <1093635866.14191.9.camel@jzny.localdomain>
2004-08-27 23:49       ` Henrik Nordstrom

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.