From: "Shawn Wright" <swright@sls.bc.ca>
To: netfilter@lists.netfilter.org
Subject: Using old CPU for 100s of clients
Date: Fri, 03 Dec 2004 12:06:27 -0800 [thread overview]
Message-ID: <41B056C3.12743.B417EB07@localhost> (raw)
Ok, I've flogged this issue on the shorewall list probably longer than some
of you can stand by now. (remember, I'm the nut trying to use a PPro200
to support ~500 users on a 10Mb internet link, and was experiencing
random slow access/timeouts on first attempts to websites, but 2nd hits
were fast. Problems can occur even during times of light load, and we
have less than 25 rules in the firewall.)
To appease those who think I'm nuts, I am ordering a new firewall shortly
to allow for future growth. (probably a Dell PE750 with P4/2.8 and dual
GE nics, although I'm open to suggestions on best choice of CPU, etc)
However, since I have yet to prove that processor speed has anything to
do with my random slow response times, I have this horrible nightmare
that I will build a brand new 2.8Ghz firewall and *have the same problem*!
(I have reproduced the problem on a PPro200 and a PII/233, but CPU
use never exceeds 15% on either, and no sign of dropped packets. A
P3/667 is currently running fine, and I am working on duplicating it's
setup, including exact kernel config on the slower machines as a test.)
So I won't bore you with any more details, but simply ask that anyone who
is using iptables/shorewall on an aging CPU (say from 100-500 Mhz)
supporting several hundred clients on a 10Mb link or faster, please let me
know, on or off list. I just hate not knowing what is causing our problems,
and having them occur on a new, fast firewall would probably push me
over the edge....
Thanks.
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Shawn Wright, I.T. Manager
Shawnigan Lake School
http://www.sls.bc.ca
swright@sls.bc.ca
next reply other threads:[~2004-12-03 20:06 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-12-03 20:06 Shawn Wright [this message]
-- strict thread matches above, loose matches on Subject: below --
2004-12-03 20:22 Using old CPU for 100s of clients Daniel Chemko
2004-12-03 21:57 ` Shawn Wright
2004-12-04 1:24 ` Shawn Wright
2004-12-04 1:27 ` Michael Gale
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=41B056C3.12743.B417EB07@localhost \
--to=swright@sls.bc.ca \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.