From mboxrd@z Thu Jan 1 00:00:00 1970 From: Stef Coene Date: Mon, 10 Mar 2003 18:00:57 +0000 Subject: Re: [LARTC] Bandwith limitation Message-Id: List-Id: References: In-Reply-To: MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: lartc@vger.kernel.org > Stef, > > We have about 3200 iptables rules on our bridge. I've tested today to > remove 1000 of these rules. The load dropped from about 40% to 25%. So I > think the iptables rule take up the most of the CPU load. Do you think this > is a problem of ineffeciency of iptables or just a 'limitation' in the > TCP/IP stack of linux ? I don't think it's a limitation. I think you reached the point where you need a bigger machine :) Maybe you can try to iptables mailing list to find more info about the performance you can expect : http://lists.netfilter.org/mailman/listinfo/netfilter Stef -- stef.coene@docum.org "Using Linux as bandwidth manager" http://www.docum.org/ #lartc @ irc.oftc.net _______________________________________________ LARTC mailing list / LARTC@mailman.ds9a.nl http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/