All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Shawn Wright" <swright@sls.bc.ca>
To: netfilter@lists.netfilter.org
Subject: Using old CPU for 100s of clients
Date: Fri, 03 Dec 2004 12:06:27 -0800	[thread overview]
Message-ID: <41B056C3.12743.B417EB07@localhost> (raw)

Ok, I've flogged this issue on the shorewall list probably longer than some 
of you can stand by now. (remember, I'm the nut trying to use a PPro200 
to support ~500 users on a 10Mb internet link, and was experiencing 
random slow access/timeouts on first attempts to websites, but 2nd hits 
were fast. Problems can occur even during times of light load, and we 
have less than 25 rules in the firewall.)

To appease those who think I'm nuts, I am ordering a new firewall shortly 
to allow for future growth. (probably a Dell PE750 with P4/2.8 and dual 
GE nics, although I'm open to suggestions on best choice of CPU, etc)

However, since I have yet to prove that processor speed has anything to 
do with my random slow response times, I have this horrible nightmare 
that I will build a brand new 2.8Ghz firewall and *have the same problem*!

(I have reproduced the problem on a PPro200 and a PII/233, but CPU 
use never exceeds 15% on either, and no sign of dropped packets. A 
P3/667 is currently running fine, and I am working on duplicating it's 
setup, including exact kernel config on the slower machines as a test.)

So I won't bore you with any more details, but simply ask that anyone who 
is using iptables/shorewall on an aging CPU (say from 100-500 Mhz) 
supporting several hundred clients on a 10Mb link or faster, please let me 
know, on or off list. I just hate not knowing what is causing our problems, 
and having them occur on a new, fast firewall would probably push me 
over the edge....

Thanks.
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Shawn Wright, I.T. Manager
Shawnigan Lake School
http://www.sls.bc.ca
swright@sls.bc.ca




             reply	other threads:[~2004-12-03 20:06 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-12-03 20:06 Shawn Wright [this message]
  -- strict thread matches above, loose matches on Subject: below --
2004-12-03 20:22 Using old CPU for 100s of clients Daniel Chemko
2004-12-03 21:57 ` Shawn Wright
2004-12-04  1:24   ` Shawn Wright
2004-12-04  1:27   ` Michael Gale

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=41B056C3.12743.B417EB07@localhost \
    --to=swright@sls.bc.ca \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.