netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: jamal <hadi@cyberus.ca>
To: Emmanuel Fleury <fleury@cs.aau.dk>
Cc: Michael Bellion <mbellion@hipac.org>,
	linux-kernel@vger.kernel.org, linux-net@vger.kernel.org,
	netdev@vger.kernel.org
Subject: Re: [ANNOUNCE] Release of nf-HiPAC 0.9.0
Date: Mon, 26 Sep 2005 07:58:01 -0400	[thread overview]
Message-ID: <1127735881.6215.294.camel@localhost.localdomain> (raw)
In-Reply-To: <4337DA7C.2000804@cs.aau.dk>

On Mon, 2005-26-09 at 13:24 +0200, Emmanuel Fleury wrote:
> Hi,
> 
> Did you solved your "size" issues when entering long list of rules ???
> 
> I'm still not convinced by your approach. :-/
> 
> These experiments have to be updated but can you comment on this:
> http://www.cs.aau.dk/~mixxel/cf/experiments.html

To repeat the tests i mentioned earlier for clarity:
a) Variable incoming packet rate (in packets per second)
b) Variable packet sizes
c) Variable number of users/filters
d) Effect of adding/removing/modifying policies while under different
incoming traffic rates.

You seem to have taken care of most of the variables involved except for
#d below. If you look at my slides you will see why #d is important to
have in modern firewalls. I think if you have to first compile rules
then you will have issues, but it remains to be seen.

Several comments:
- Am i mistaken that your source of data is from somewhere in the
backbone? Would it be fair to say that something in the edge would be
more appropriate?

- Your header extraction tool creates "10 sets of rules"; is there a
reason for the number 10?

- Is tcpreplay the right tool? What does it give you that you cant use a
better blaster like pktgen?

- I think the blackbox monitor looking at the input vs output tool is
good. It will be more complete if you can quantify the input rate then
you can easily quantify output rate.

- While your results were useful in showing Mbps; they are incomplete by
not mentioning the packet size. A better metric would have been pps. But
even then mentioning packet size is also useful.

If you are going to run these tests in stateless firewalling as you did,
please consider using tc filter as well.

cheers,
jamal

  parent reply	other threads:[~2005-09-26 11:58 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <200509260445.46740.mbellion@hipac.org>
2005-09-26 11:18 ` [ANNOUNCE] Release of nf-HiPAC 0.9.0 jamal
2005-09-26 11:24 ` Emmanuel Fleury
     [not found] ` <4337DA7C.2000804@cs.aau.dk>
2005-09-26 11:58   ` jamal [this message]
2005-09-26 12:13     ` Emmanuel Fleury
2005-09-26 12:40       ` jamal
2005-09-26 14:38   ` Michael Bellion
     [not found]   ` <200509261638.12731.mbellion@hipac.org>
2005-09-26 15:05     ` Emmanuel Fleury
     [not found]     ` <43380E4A.1060604@cs.aau.dk>
2005-09-26 16:03       ` Michael Bellion
     [not found]       ` <200509261803.28150.mbellion@hipac.org>
2005-09-26 16:31         ` Emmanuel Fleury
2005-10-06 15:09     ` Bill Davidsen
     [not found] ` <1127733492.6215.274.camel@localhost.localdomain>
2005-09-26 13:16   ` Michael Bellion
     [not found]   ` <200509261516.16565.mbellion@hipac.org>
2005-09-26 13:31     ` jamal
2005-09-30 12:33 ` Harald Welte
     [not found] ` <20050930123334.GW4168@sunbeam.de.gnumonks.org>
2005-10-01 15:38   ` Michael Bellion
2005-09-26  2:45 Michael Bellion

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1127735881.6215.294.camel@localhost.localdomain \
    --to=hadi@cyberus.ca \
    --cc=fleury@cs.aau.dk \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-net@vger.kernel.org \
    --cc=mbellion@hipac.org \
    --cc=netdev@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).