All of lore.kernel.org
 help / color / mirror / Atom feed
* iptables performance under 2.6.0[-test9]
@ 2003-10-27 16:10 Andy Polyakov
  2003-10-27 18:05 ` Andy Polyakov
  0 siblings, 1 reply; 10+ messages in thread
From: Andy Polyakov @ 2003-10-27 16:10 UTC (permalink / raw)
  To: netfilter-devel

Hi,

I tried to deploy 2.6.0[-test9] iptables to masquarade an private
interace. Strangely enough ip_conntrack.ko module seems to affect
performance of *some* TCP connections. More specific I found that
performance of certain TCP connections (netscape mail rebuilding index
of an large IMAP mailbox in my case) is *reproducibly* unacceptable
(minutes vs. normal 15-20 seconds). In the course of troubleshooting I
started to unload iptables modules one by one, and after 'rmmod
ip_conntrack,' performance became normal. I don't know if it's
essential, but performance is not affected if I deploy ipchains instead
of iptables for equivalent setup. Oh! Those affected TCP connections are
*not* masqueraded and are "bound" to primary interface. I'm looking for
triggering factors now (what's so special about netscape mail rebuilding
mailbox index), but I figured that meanwhile it might worth asking
people on this list if this resembles any other problem report. Does it?
A.

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2003-10-29  0:32 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-10-27 16:10 iptables performance under 2.6.0[-test9] Andy Polyakov
2003-10-27 18:05 ` Andy Polyakov
2003-10-27 18:30   ` Andy Polyakov
2003-10-28  8:30   ` Patrick McHardy
2003-10-28 10:01     ` Andy Polyakov
2003-10-28 10:09       ` Patrick McHardy
2003-10-28 11:18         ` Andy Polyakov
2003-10-28 12:19           ` Patrick McHardy
2003-10-28 21:59             ` Andy Polyakov
2003-10-29  0:32               ` Patrick McHardy

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.