* Speed Issues through NAT Firewall
@ 2002-07-09 17:29 Travis Crook
2002-07-09 17:38 ` Ramin Alidousti
` (2 more replies)
0 siblings, 3 replies; 13+ messages in thread
From: Travis Crook @ 2002-07-09 17:29 UTC (permalink / raw)
To: netfilter
[-- Attachment #1: Type: text/plain, Size: 495 bytes --]
Hello,
I currently have two firewalls running. Both on Mandrake 8.1 running iptables. I currently have two internet connections (one is a DSL line at 1Mb, the other is straight from an ISP at 2.5 Mb). I can get 700Kb speeds through the firewall on the DSL line (which is about as fast as it ever is) but I only get about 500Kb speeds through the firewall on the ISP line. Shouldn't I be able to get at least 2Mb speeds through this firewall?
Thanks
Travis Crook
Visions Beyond
[-- Attachment #2: Type: text/html, Size: 891 bytes --]
^ permalink raw reply [flat|nested] 13+ messages in thread* Re: Speed Issues through NAT Firewall
2002-07-09 17:29 Speed Issues through NAT Firewall Travis Crook
@ 2002-07-09 17:38 ` Ramin Alidousti
2002-07-09 17:59 ` Travis Crook
2002-07-09 17:49 ` Patrick Schaaf
2002-07-09 17:53 ` Antony Stone
2 siblings, 1 reply; 13+ messages in thread
From: Ramin Alidousti @ 2002-07-09 17:38 UTC (permalink / raw)
To: Travis Crook; +Cc: netfilter
On Tue, Jul 09, 2002 at 11:29:49AM -0600, Travis Crook wrote:
> Hello,
> I currently have two firewalls running. Both on Mandrake 8.1 running iptables. I currently have two internet connections (one is a DSL line at 1Mb, the other is straight from an ISP at 2.5 Mb). I can get 700Kb speeds through the firewall on the DSL line (which is about as fast as it ever is) but I only get about 500Kb speeds through the firewall on the ISP line. Shouldn't I be able to get at least 2Mb speeds through this firewall?
How do you measure the throughput?
Ramin
PS. Line breaks are good things.
>
> Thanks
>
> Travis Crook
> Visions Beyond
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: Speed Issues through NAT Firewall
2002-07-09 17:38 ` Ramin Alidousti
@ 2002-07-09 17:59 ` Travis Crook
2002-07-09 18:28 ` Ramin Alidousti
0 siblings, 1 reply; 13+ messages in thread
From: Travis Crook @ 2002-07-09 17:59 UTC (permalink / raw)
To: Ramin Alidousti; +Cc: netfilter
> Hello,
> I currently have two firewalls running. Both on Mandrake 8.1 running
iptables. I currently have two internet connections (one is a DSL line at
1Mb, the other is straight from an ISP at 2.5 Mb). I can get 700Kb speeds
through the firewall on the DSL line (which is about as fast as it ever is)
but I only get about 500Kb speeds through the firewall on the ISP line.
Shouldn't I be able to get at least 2Mb speeds through this firewall?
>
> How do you measure the throughput?
I used http://promos.mcafee.com/speedometer and http://www.dslreports.com.
I can get 3Mb testing on the firewall itself but not on a machine behind the
firewall.
> Ramin
> PS. Line breaks are good things.
I'll use more linebreaks. Thanks!
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: Speed Issues through NAT Firewall
2002-07-09 17:59 ` Travis Crook
@ 2002-07-09 18:28 ` Ramin Alidousti
0 siblings, 0 replies; 13+ messages in thread
From: Ramin Alidousti @ 2002-07-09 18:28 UTC (permalink / raw)
To: Travis Crook; +Cc: Ramin Alidousti, netfilter
On Tue, Jul 09, 2002 at 11:59:56AM -0600, Travis Crook wrote:
> > Hello,
> > I currently have two firewalls running. Both on Mandrake 8.1 running
> iptables. I currently have two internet connections (one is a DSL line at
> 1Mb, the other is straight from an ISP at 2.5 Mb). I can get 700Kb speeds
> through the firewall on the DSL line (which is about as fast as it ever is)
> but I only get about 500Kb speeds through the firewall on the ISP line.
> Shouldn't I be able to get at least 2Mb speeds through this firewall?
> >
> > How do you measure the throughput?
>
> I used http://promos.mcafee.com/speedometer and http://www.dslreports.com.
> I can get 3Mb testing on the firewall itself but not on a machine behind the
> firewall.
Haven't been able to check the second site but the first one sends you a
file and measures the actual download time. Now, imagine what happens when
there is congestion along the path. Your throughput would show a very low
number while the actual problem does not have anything to do with you and/or
your upstream router.
The reason for your "ISP line" showing 500kb and the "DSL line" showing 700Kb
is IMO irrelevant to the netfilter overhead/througput. However, the delta between
the same test done (a) on the firewall (b) from behind the firewall might
be an indication of how fast (or slow, for that matter) the firewall machine
is forwarding the packets.
Like Patrick has pointed out, first of all you need to make sure that your
devices and the wiring is healthy, though.
Ramin
>
> > Ramin
> > PS. Line breaks are good things.
>
> I'll use more linebreaks. Thanks!
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: Speed Issues through NAT Firewall
2002-07-09 17:29 Speed Issues through NAT Firewall Travis Crook
2002-07-09 17:38 ` Ramin Alidousti
@ 2002-07-09 17:49 ` Patrick Schaaf
2002-07-09 17:57 ` Travis Crook
2002-07-09 17:53 ` Antony Stone
2 siblings, 1 reply; 13+ messages in thread
From: Patrick Schaaf @ 2002-07-09 17:49 UTC (permalink / raw)
To: Travis Crook; +Cc: netfilter
> I currently have two firewalls running. Both on Mandrake 8.1 running iptables. I currently have two internet connections (one is a DSL line at 1Mb, the other is straight from an ISP at 2.5 Mb). I can get 700Kb speeds through the firewall on the DSL line (which is about as fast as it ever is) but I only get about 500Kb speeds through the firewall on the ISP line. Shouldn't I be able to get at least 2Mb speeds through this firewall?
At least you can be almost assured that your problems have nothing to
do with iptables and it's NAT. Starting up my crystal ball, I predict
you'll find some half/full duplex mismatch on one of your Ethernets.
Oh, and what type and speed are your CPUs?
best regards
Patrick
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: Speed Issues through NAT Firewall
2002-07-09 17:49 ` Patrick Schaaf
@ 2002-07-09 17:57 ` Travis Crook
2002-07-09 18:08 ` Antony Stone
0 siblings, 1 reply; 13+ messages in thread
From: Travis Crook @ 2002-07-09 17:57 UTC (permalink / raw)
To: Patrick Schaaf; +Cc: netfilter
The firewall on the DSL is an Athlon XP 1500+. The firewall on the ISP line
is a PII 333. I will check on the full/half duplex issue.
Travis Crook
Visions Beyond
----- Original Message -----
From: "Patrick Schaaf" <bof@bof.de>
To: "Travis Crook" <travis@visionsbeyond.com>
Cc: <netfilter@lists.samba.org>
Sent: Tuesday, July 09, 2002 11:49 AM
Subject: Re: Speed Issues through NAT Firewall
> > I currently have two firewalls running. Both on Mandrake 8.1
running iptables. I currently have two internet connections (one is a DSL
line at 1Mb, the other is straight from an ISP at 2.5 Mb). I can get 700Kb
speeds through the firewall on the DSL line (which is about as fast as it
ever is) but I only get about 500Kb speeds through the firewall on the ISP
line. Shouldn't I be able to get at least 2Mb speeds through this firewall?
>
> At least you can be almost assured that your problems have nothing to
> do with iptables and it's NAT. Starting up my crystal ball, I predict
> you'll find some half/full duplex mismatch on one of your Ethernets.
> Oh, and what type and speed are your CPUs?
>
> best regards
> Patrick
>
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: Speed Issues through NAT Firewall
2002-07-09 17:57 ` Travis Crook
@ 2002-07-09 18:08 ` Antony Stone
2002-07-09 18:25 ` Martin Josefsson
0 siblings, 1 reply; 13+ messages in thread
From: Antony Stone @ 2002-07-09 18:08 UTC (permalink / raw)
To: netfilter
On Tuesday 09 July 2002 6:57 pm, Travis Crook wrote:
> The firewall on the DSL is an Athlon XP 1500+. The firewall on the ISP
> line is a PII 333. I will check on the full/half duplex issue.
That's a hell of a difference, and could conceivably account for the
bandwidth. I'd say it depends on how much RAM you have in the PII/333 and
how many connections you're trying to support.
Antony.
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: Speed Issues through NAT Firewall
2002-07-09 18:08 ` Antony Stone
@ 2002-07-09 18:25 ` Martin Josefsson
2002-07-09 18:49 ` Ramin Alidousti
2002-07-09 19:32 ` Antony Stone
0 siblings, 2 replies; 13+ messages in thread
From: Martin Josefsson @ 2002-07-09 18:25 UTC (permalink / raw)
To: Antony Stone; +Cc: Netfilter
On Tue, 2002-07-09 at 20:08, Antony Stone wrote:
> On Tuesday 09 July 2002 6:57 pm, Travis Crook wrote:
>
> > The firewall on the DSL is an Athlon XP 1500+. The firewall on the ISP
> > line is a PII 333. I will check on the full/half duplex issue.
>
> That's a hell of a difference, and could conceivably account for the
> bandwidth. I'd say it depends on how much RAM you have in the PII/333 and
> how many connections you're trying to support.
No way a pII 333 is to slow to handle 2Mbit/s, my old 486 can handle
that easily. You would have to trash the conntrack hashtable with
multiple attacks to even have a chance of getting it that slow.
I also believe there's a duplex-mismatch somewhere, probably between the
firewall and the internal network.
--
/Martin
Never argue with an idiot. They drag you down to their level, then beat
you with experience.
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: Speed Issues through NAT Firewall
2002-07-09 18:25 ` Martin Josefsson
@ 2002-07-09 18:49 ` Ramin Alidousti
2002-07-09 19:32 ` Antony Stone
1 sibling, 0 replies; 13+ messages in thread
From: Ramin Alidousti @ 2002-07-09 18:49 UTC (permalink / raw)
To: Martin Josefsson; +Cc: Antony Stone, Netfilter
On Tue, Jul 09, 2002 at 08:25:45PM +0200, Martin Josefsson wrote:
> > > The firewall on the DSL is an Athlon XP 1500+. The firewall on the ISP
> > > line is a PII 333. I will check on the full/half duplex issue.
> >
> > That's a hell of a difference, and could conceivably account for the
> > bandwidth. I'd say it depends on how much RAM you have in the PII/333 and
> > how many connections you're trying to support.
>
> No way a pII 333 is to slow to handle 2Mbit/s, my old 486 can handle
> that easily. You would have to trash the conntrack hashtable with
> multiple attacks to even have a chance of getting it that slow.
>
> I also believe there's a duplex-mismatch somewhere, probably between the
> firewall and the internal network.
In that case a simple ping flood across the suspicious link can help...
Ramin
>
> --
> /Martin
>
> Never argue with an idiot. They drag you down to their level, then beat
> you with experience.
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: Speed Issues through NAT Firewall
2002-07-09 18:25 ` Martin Josefsson
2002-07-09 18:49 ` Ramin Alidousti
@ 2002-07-09 19:32 ` Antony Stone
2002-07-09 23:08 ` Travis Crook
1 sibling, 1 reply; 13+ messages in thread
From: Antony Stone @ 2002-07-09 19:32 UTC (permalink / raw)
To: Netfilter
On Tuesday 09 July 2002 7:25 pm, Martin Josefsson wrote:
> On Tue, 2002-07-09 at 20:08, Antony Stone wrote:
> > On Tuesday 09 July 2002 6:57 pm, Travis Crook wrote:
> > > The firewall on the DSL is an Athlon XP 1500+. The firewall on the ISP
> > > line is a PII 333. I will check on the full/half duplex issue.
> >
> > That's a hell of a difference, and could conceivably account for the
> > bandwidth. I'd say it depends on how much RAM you have in the PII/333
> > and how many connections you're trying to support.
>
> No way a pII 333 is to slow to handle 2Mbit/s, my old 486 can handle
> that easily. You would have to trash the conntrack hashtable with
> multiple attacks to even have a chance of getting it that slow.
I only said it could *conceivably* account for the bandwidth limit - I didn't
say it was likely. I agree with you that a 486 can easily exceed this
performance, but it depends what Travis is doing with the system - last
summer I saw netfilter boxes reduced to tens of kbits/sec bandwidth by Nimda
and Code Red saturating the conntracking tables with half-open links.
I agree with several people here that Travis should check the hardware first,
and I would also recommend testing the bandwidth by doing several downloads
simultaneously from sites with high-bandwidth links, as close (in hops) to
his machine as possible.
Antony.
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: Speed Issues through NAT Firewall
2002-07-09 19:32 ` Antony Stone
@ 2002-07-09 23:08 ` Travis Crook
0 siblings, 0 replies; 13+ messages in thread
From: Travis Crook @ 2002-07-09 23:08 UTC (permalink / raw)
To: Antony Stone; +Cc: netfilter
> I agree with several people here that Travis should check the hardware
first,
> and I would also recommend testing the bandwidth by doing several
downloads
> simultaneously from sites with high-bandwidth links, as close (in hops) to
> his machine as possible.
>
> Antony.
I checked the hardware. Everything is running 100baseTx-FD (100 mb full
duplex). I used several different workstations and found the problem. If I
test with a Windows 98 box I get 500Kb. If I test with a Windows 2000 box I
get 1Mb, if I test with a Linux box I get 3.5Mb. Windows must have some
kind of internet throttling.
Yet another reason to use Linux.
Thanks Everyone for your help!
Travis Crook
Visions Beyond
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: Speed Issues through NAT Firewall
2002-07-09 17:29 Speed Issues through NAT Firewall Travis Crook
2002-07-09 17:38 ` Ramin Alidousti
2002-07-09 17:49 ` Patrick Schaaf
@ 2002-07-09 17:53 ` Antony Stone
2 siblings, 0 replies; 13+ messages in thread
From: Antony Stone @ 2002-07-09 17:53 UTC (permalink / raw)
To: netfilter
On Tuesday 09 July 2002 6:29 pm, Travis Crook wrote:
> Hello,
> I currently have two firewalls running. Both on Mandrake 8.1 running
> iptables. I currently have two internet connections (one is a DSL line at
> 1Mb, the other is straight from an ISP at 2.5 Mb). I can get 700Kb speeds
> through the firewall on the DSL line (which is about as fast as it ever is)
> but I only get about 500Kb speeds through the firewall on the ISP line.
> Shouldn't I be able to get at least 2Mb speeds through this firewall?
What's your hardware (CPU, RAM, NIC) ?
How many connections do you have concurrently through the boxes ?
Quick way to get a rough idea:
wc -l /proc/net/ip_conntrack
Antony.
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: Speed Issues through NAT Firewall
@ 2002-07-09 19:03 j davis
0 siblings, 0 replies; 13+ messages in thread
From: j davis @ 2002-07-09 19:03 UTC (permalink / raw)
To: netfilter
also...do
mii-tool from the command line to see your duplex and you
can use a program called bing to test through put between
2 interfaces.
jd
http://www.taproot.bz
>From: Antony Stone <Antony@Soft-Solutions.co.uk>
>To: <netfilter@lists.samba.org>
>Subject: Re: Speed Issues through NAT Firewall
>Date: Tue, 9 Jul 2002 19:08:22 +0100
>MIME-Version: 1.0
>Received: from [198.186.203.85] by hotmail.com (3.2) with ESMTP id
>MHotMailBEF47481004D40043251C6BACB559E280; Tue, 09 Jul 2002 11:20:56 -0700
>Received: from va.samba.org (localhost [127.0.0.1])by lists.samba.org
>(Postfix) with ESMTPid A0731495C; Tue, 9 Jul 2002 11:20:47 -0700 (PDT)
>Received: from vulcan.rissington.net (mail.rissington.net
>[213.121.241.158])by lists.samba.org (Postfix) with ESMTP id 57318495Efor
><netfilter@lists.samba.org>; Tue, 9 Jul 2002 11:08:40 -0700 (PDT)
>Received: from there (dhcp211 [192.168.192.211] (may be forged))by
>vulcan.rissington.net (8.10.2/8.10.2) with SMTP id g69I8R810149for
><netfilter@lists.samba.org>; Tue, 9 Jul 2002 19:08:27 +0100
From netfilter-admin@lists.samba.org Tue, 09 Jul 2002 11:21:44 -0700
>Delivered-To: netfilter@lists.samba.org
>Message-Id: <200207091808.g69I8R810149@vulcan.rissington.net>
>Organization: Software Solutions
>X-Mailer: KMail [version 1.3.2]
>References: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com>
><20020709194926.A17608@oknodo.bof.de>
><005501c22772$1ef01240$6702a8c0@mindtrip.com>
>In-Reply-To: <005501c22772$1ef01240$6702a8c0@mindtrip.com>
>Sender: netfilter-admin@lists.samba.org
>Errors-To: netfilter-admin@lists.samba.org
>X-BeenThere: netfilter@lists.samba.org
>X-Mailman-Version: 2.0.8
>Precedence: bulk
>List-Help: <mailto:netfilter-request@lists.samba.org?subject=help>
>List-Post: <mailto:netfilter@lists.samba.org>
>List-Subscribe:
><http://lists.samba.org/listinfo/netfilter>,<mailto:netfilter-request@lists.samba.org?subject=subscribe>
>List-Id: netfilter user discussion list <netfilter.lists.samba.org>
>List-Unsubscribe:
><http://lists.samba.org/listinfo/netfilter>,<mailto:netfilter-request@lists.samba.org?subject=unsubscribe>
>List-Archive: <http://lists.samba.org/pipermail/netfilter/>
>
>On Tuesday 09 July 2002 6:57 pm, Travis Crook wrote:
>
> > The firewall on the DSL is an Athlon XP 1500+. The firewall on the ISP
> > line is a PII 333. I will check on the full/half duplex issue.
>
>That's a hell of a difference, and could conceivably account for the
>bandwidth. I'd say it depends on how much RAM you have in the PII/333 and
>how many connections you're trying to support.
>
>
>
>Antony.
>
thanks,
jd
jd@taproot.bz
http://www.taproot.bz
thanks,
jd
jd@taproot.bz
http://www.taproot.bz
_________________________________________________________________
Chat with friends online, try MSN Messenger: http://messenger.msn.com
^ permalink raw reply [flat|nested] 13+ messages in thread
end of thread, other threads:[~2002-07-09 23:08 UTC | newest]
Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-07-09 17:29 Speed Issues through NAT Firewall Travis Crook
2002-07-09 17:38 ` Ramin Alidousti
2002-07-09 17:59 ` Travis Crook
2002-07-09 18:28 ` Ramin Alidousti
2002-07-09 17:49 ` Patrick Schaaf
2002-07-09 17:57 ` Travis Crook
2002-07-09 18:08 ` Antony Stone
2002-07-09 18:25 ` Martin Josefsson
2002-07-09 18:49 ` Ramin Alidousti
2002-07-09 19:32 ` Antony Stone
2002-07-09 23:08 ` Travis Crook
2002-07-09 17:53 ` Antony Stone
-- strict thread matches above, loose matches on Subject: below --
2002-07-09 19:03 j davis
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox