From mboxrd@z Thu Jan 1 00:00:00 1970 From: Samuel Jean Subject: Re: Performance isues related to a large number of iptables rules Date: Thu, 13 Jan 2005 20:32:46 -0500 Message-ID: <41E7213E.9080202@cookinglinux.org> References: <41E6FA0E.2060707@intellitree.com> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <41E6FA0E.2060707@intellitree.com> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-bounces@lists.netfilter.org Errors-To: netfilter-bounces@lists.netfilter.org Content-Type: text/plain; charset="us-ascii"; format="flowed" To: henry Cc: netfilter@lists.netfilter.org henry wrote: > Does anyone know what the real numbers are, and > what numbers are feasible and what numbers aren't? > Not me. But if blocking large amount of subnets and host addresses is your issue here. Only one rule is sufficient. See ipset 2.0 http://people.netfilter.org/kadlec/ipset/ Sorry if am out of topic. Samuel