From: Alexander Sirotkin <demiurg@metalinkBB.com>
To: Robert Iakobashvili <coroberti@gmail.com>
Cc: netfilter-devel@lists.netfilter.org
Subject: Re: netfilter performance on low-end embedded systems
Date: Wed, 14 Feb 2007 11:31:11 +0200 [thread overview]
Message-ID: <45D2D6DF.4030200@metalinkbb.com> (raw)
In-Reply-To: <7e63f56c0702120822v4d4d27cble4d9c07afc40741d@mail.gmail.com>
Robert Iakobashvili wrote:
> Alexander,
>
>
>> From: Alexander Sirotkin <demiurg@metalinkBB.com>
>
>> I'm trying to evaluate the feasibility of using netfilter on low-end
>> embedded processors, such as MIPS 4K or 24K. Basicly what I'm trying to
>> understand is whether we can do 100Bps with netfilter enabled (firewall
>> and NAT) on such a CPU or should we check hardware acceleration
>> solution.
>>
>> If anybody did any similar benchmarks and can share results (does not
>> have to be on MIPS) or just has any opinion on the subject - I'd be very
>> grateful.
>
> With reference to the low-end arm processors, high traffic is not a
> problem, unless
> you are not using a large number of iptables rules, which traversal by
> packets
> is linear.
Well, this is not entirely correct.
I started doing some benchmarks myself on MIPS 24K 266MHz which is
fairly common embedded CPU and the results are not very good. Under
100Mbps UDP traffic just compiling netfilter increases CPU utilization
by 20%.
Profiling shows that most time is spent in nf_hook_slow (8%) and
nf_iterate (7%) functions. I can post more results in case anybody is
interested to discuss this.
> If you need lots many rules, e.g. hundreds, thousands, etc, consider
> using various
> flavors of ipset, nf-hypac, connection tracking, wise rules
> arrangement, etc.
>
>
> Sincerely,
> Robert Iakobashvili,
> coroberti %x40 gmail %x2e com
> ...................................................................
> Navigare necesse est, vivere non est necesse
> ...................................................................
> http://sourceforge.net/projects/curl-loader
> A powerful open-source HTTP/S, FTP/S traffic
> generating, loading and testing tool.
--
Alexander Sirotkin
System Engineer
System Architecture Group
Metalink Broadband Ltd.
Phone: +972-9-9605360
Fax: +972-9-9605344
Mobile: +972-54-4959034
-- Disclaimer: --
This e-mail is intended solely for the person to whom it is addressed and may contain confidential or legally privileged information. Access to this e-mail by anyone else is unauthorized. If an addressing or transmission error has misdirected this e-mail, please notify the author by replying to this e-mail and destroy this e-mail and any attachments.
E-mail may be susceptible to data corruption, interception, unauthorized amendment, viruses and delays or the consequences thereof. If you are not the intended recipient, be advised that you have received this email in error and that any use, dissemination, forwarding, printing or copying of this email is strictly prohibited.
next prev parent reply other threads:[~2007-02-14 9:31 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-02-12 16:22 netfilter performance on low-end embedded systems Robert Iakobashvili
2007-02-14 9:31 ` Alexander Sirotkin [this message]
-- strict thread matches above, loose matches on Subject: below --
2007-01-10 8:17 Alexander Sirotkin
2007-01-07 13:24 Alexander Sirotkin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=45D2D6DF.4030200@metalinkbb.com \
--to=demiurg@metalinkbb.com \
--cc=coroberti@gmail.com \
--cc=netfilter-devel@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).