All of lore.kernel.org
 help / color / mirror / Atom feed
* status of nf-HIPAC integration ?
@ 2006-08-21 14:57 Steven Van Acker
  2006-08-23  7:50 ` Jeho Park
  0 siblings, 1 reply; 4+ messages in thread
From: Steven Van Acker @ 2006-08-21 14:57 UTC (permalink / raw)
  To: netfilter-devel, mbellion; +Cc: kulnet

Hello,

for some time now we have been using the nf-HIPAC patch in our firewalls' kernels
and I'm glad to say it works nicely. Our firewalls still run 2.4.x kernels. Ever 
since the introduction of x-tables in the 2.6.x branch, the nf-HIPAC patch no 
longer applies.

I found a patch at 
http://www.kernelproject.org/people/jhpark/nf-hipac-0.9.1-to-linux-2.6.16.16.patch
by Jeho-Park, which should allow me to compile 2.6.16.16 with nf-HIPAC. 

Has anyone tried this patch ?

I'm not sure what the future of nf-HIPAC is. I'd like it very much if the 
mainstream kernel came with nf-HIPAC by default, but I see no indications that 
anything is moving in that direction.

Is nf-HIPAC still being worked on ?
Is it still on the TODO-list to integrate nf-HIPAC into the mainstream kernel ?

kind regards,
-- Steven Van Acker

-- 
My amazon wishlist:
http://www.amazon.com/gp/registry/1DB4XNEIEQBPB

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: status of nf-HIPAC integration ?
  2006-08-21 14:57 status of nf-HIPAC integration ? Steven Van Acker
@ 2006-08-23  7:50 ` Jeho Park
  2006-08-23 11:29   ` Patrick McHardy
  0 siblings, 1 reply; 4+ messages in thread
From: Jeho Park @ 2006-08-23  7:50 UTC (permalink / raw)
  To: Steven Van Acker; +Cc: mbellion, netfilter-devel, kulnet

hi steven


Steven Van Acker wrote:

>Hello,
>
>for some time now we have been using the nf-HIPAC patch in our firewalls' kernels
>and I'm glad to say it works nicely. Our firewalls still run 2.4.x kernels. Ever 
>since the introduction of x-tables in the 2.6.x branch, the nf-HIPAC patch no 
>longer applies.
>
>I found a patch at 
>http://www.kernelproject.org/people/jhpark/nf-hipac-0.9.1-to-linux-2.6.16.16.patch
>by Jeho-Park, which should allow me to compile 2.6.16.16 with nf-HIPAC. 
>
>Has anyone tried this patch ?
>
>  
>
yes, i applied that patch to the standard linux 2.6.16.16 ~ 2.6.16.18 
and 2.6.17.3
the patch include original nf-hipac patch v 0.9.2 and somewhat bit 
changes which as you know, stemed from x-tables

todays, i tested thputs with smartbits (nf-hipac vs iptables) in the 
kernel 2.6.17.3
result URL:
http://www.kernelproject.org/people/jhpark/fw_thput_test1.htm

the result looks somewhat ugly because thput result is much low.
but as you refer my result, you can compare thput of the iptables with 
that of the nf-hipac in the kernel 2.6.17.3

test variable is like this : rule number, packet size, ...

the patch include original nf-hipac patch v 0.9.2 and somewhat bit 
changes which as you know, stemed from x-tables

thanks

---
jeho park <jhpark-nf@kernelproject.org>

>I'm not sure what the future of nf-HIPAC is. I'd like it very much if the 
>mainstream kernel came with nf-HIPAC by default, but I see no indications that 
>anything is moving in that direction.
>
>Is nf-HIPAC still being worked on ?
>Is it still on the TODO-list to integrate nf-HIPAC into the mainstream kernel ?
>
>kind regards,
>-- Steven Van Acker
>
>  
>

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: status of nf-HIPAC integration ?
  2006-08-23  7:50 ` Jeho Park
@ 2006-08-23 11:29   ` Patrick McHardy
  2006-08-23 14:03     ` Jeho Park
  0 siblings, 1 reply; 4+ messages in thread
From: Patrick McHardy @ 2006-08-23 11:29 UTC (permalink / raw)
  To: Jeho Park; +Cc: mbellion, netfilter-devel, kulnet, Steven Van Acker

Jeho Park wrote:
> todays, i tested thputs with smartbits (nf-hipac vs iptables) in the
> kernel 2.6.17.3
> result URL:
> http://www.kernelproject.org/people/jhpark/fw_thput_test1.htm
> 
> the result looks somewhat ugly because thput result is much low.
> but as you refer my result, you can compare thput of the iptables with
> that of the nf-hipac in the kernel 2.6.17.3

That indeed looks ugly (for iptables). How was the ruleset structured?
Could you put it on your page please?

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: status of nf-HIPAC integration ?
  2006-08-23 11:29   ` Patrick McHardy
@ 2006-08-23 14:03     ` Jeho Park
  0 siblings, 0 replies; 4+ messages in thread
From: Jeho Park @ 2006-08-23 14:03 UTC (permalink / raw)
  To: Patrick McHardy; +Cc: mbellion, Steven Van Acker, netfilter-devel, kulnet

Patrick McHardy wrote:

>Jeho Park wrote:
>  
>
>>todays, i tested thputs with smartbits (nf-hipac vs iptables) in the
>>kernel 2.6.17.3
>>result URL:
>>http://www.kernelproject.org/people/jhpark/fw_thput_test1.htm
>>
>>the result looks somewhat ugly because thput result is much low.
>>but as you refer my result, you can compare thput of the iptables with
>>that of the nf-hipac in the kernel 2.6.17.3
>>    
>>
>
>That indeed looks ugly (for iptables). How was the ruleset structured?
>Could you put it on your page please?
>
>
>
>
>  
>
i uploaded the scripts.



rule 1000 hipac script:
http://www.kernelproject.org/people/jhpark/fw_forward1000_hp


rule 1000 iptables script:
http://www.kernelproject.org/people/jhpark/fw_forward1000_ipt


rule 2000 hipac script:
http://www.kernelproject.org/people/jhpark/fw_forward2000_hp


rule 2000 iptables script: 
http://www.kernelproject.org/people/jhpark/fw_forward2000_ipt



and above all, i fixed some my mistake. the router was not zeon dual
core but pentium-4 2.4G


so i fixed the result document (
http://www.kernelproject.org/people/jhpark/fw_thput_test1.htm
) 



p.s: 


the commands,  ipt and hp, in the scripts above are somewhat
changed iptables and nf-hipac command.


because i want to access any firewall ruleset with its unique ID for
convience, so i modified netfilter,


hipac kernel code and their user commands (iptables, nf-hipac)




thanks 



--


jeho park <jhpark-nf@kernelproject.org>

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2006-08-23 14:03 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-08-21 14:57 status of nf-HIPAC integration ? Steven Van Acker
2006-08-23  7:50 ` Jeho Park
2006-08-23 11:29   ` Patrick McHardy
2006-08-23 14:03     ` Jeho Park

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.