From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Michael Albrecht" Subject: Performance losings with iptables Date: Tue, 13 May 2003 17:57:28 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <00ec01c31968$5b3bba40$3a51a8c0@memmingen> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_00E9_01C31979.1E738410" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_00E9_01C31979.1E738410 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hello, i use iptables with Debian-Linux (2.4.20). Wenn i install 150 Input-Chains like this: iptables -A input -s 192.168.81.xxx i will lose a lot of perfomance (for example: apache take a lot of time, = ssh ...) Wenn i show the perfomance with vmstat - vmstat says that 99 % is = idel... Wer is the Problem ??? Thanks for helping ... Michael ------=_NextPart_000_00E9_01C31979.1E738410 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
 
Hello,
i use iptables with Debian-Linux=20 (2.4.20).
Wenn i install 150 Input-Chains like=20 this:
iptables -A input -s = 192.168.81.xxx
i will lose a lot of perfomance (for = example:=20 apache take a lot of time, ssh ...)
Wenn i show the perfomance with vmstat = - vmstat=20 says that 99 % is idel...
Wer is the Problem ???
 
Thanks for helping ...=20 Michael
------=_NextPart_000_00E9_01C31979.1E738410-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Aldo Lagana" Subject: RE: Performance losings with iptables Date: Tue, 13 May 2003 12:48:48 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <200305131651.h4DGprlN010480@discmail.com> References: <00ec01c31968$5b3bba40$3a51a8c0@memmingen> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0086_01C3194D.FFA51150" Return-path: In-Reply-To: <00ec01c31968$5b3bba40$3a51a8c0@memmingen> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: 'Michael Albrecht' , netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_0086_01C3194D.FFA51150 Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: quoted-printable not sure what version of iptables you have, but I have 707 rules in all = the various tables of filter and nat - none in the mangle table yet I have = seen zero (0) performance degradation on a P3 500 that also runs squid proxy, = has a DMZ with a web farm, and has about 100 ipsec tunnels=20 _____ =20 From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Michael = Albrecht Sent: Tuesday, May 13, 2003 11:57 AM To: netfilter@lists.netfilter.org =20 Hello, i use iptables with Debian-Linux (2.4.20). Wenn i install 150 Input-Chains like this: iptables -A input -s 192.168.81.xxx i will lose a lot of perfomance (for example: apache take a lot of time, = ssh ...) Wenn i show the perfomance with vmstat - vmstat says that 99 % is = idel... Wer is the Problem ??? =20 Thanks for helping ... Michael ------=_NextPart_000_0086_01C3194D.FFA51150 Content-Type: text/html; charset="US-ASCII" Content-Transfer-Encoding: quoted-printable
not=20 sure what version of iptables you have, but I have 707 rules in all the = various=20 tables of filter and nat - none in the mangle table yet I have seen=20 zero (0) performance degradation on a P3 500 that also runs squid proxy, = has a=20 DMZ with a web farm, and has about 100 ipsec tunnels =



From: = netfilter-admin@lists.netfilter.org=20 [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of = Michael=20 Albrecht
Sent: Tuesday, May 13, 2003 11:57 AM
To:=20 netfilter@lists.netfilter.org

 
Hello,
i use iptables with Debian-Linux=20 (2.4.20).
Wenn i install 150 Input-Chains like=20 this:
iptables -A input -s = 192.168.81.xxx
i will lose a lot of perfomance (for = example:=20 apache take a lot of time, ssh ...)
Wenn i show the perfomance with = vmstat - vmstat=20 says that 99 % is idel...
Wer is the Problem ???
 
Thanks for helping ...=20 Michael
------=_NextPart_000_0086_01C3194D.FFA51150-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Michael Albrecht" Subject: Performance losings with iptables Date: Tue, 13 May 2003 17:40:32 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <007d01c31965$fe099ce0$3a51a8c0@memmingen> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_007A_01C31976.C0A8A920" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_007A_01C31976.C0A8A920 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hello, i use iptables with Debian-Linux (2.4.20). Wenn i install 150 Input-Chains like this: iptables -A input -s 192.168.81.xxx i will lose a lot of perfomance (for example: apache take a lot of time, = ssh ...) Wenn i show the perfomance with vmstat - vmstat says that 99 % is = idel... Wer is the Problem ??? Thanks for helping ... Michael ------=_NextPart_000_007A_01C31976.C0A8A920 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Hello,
i use iptables with Debian-Linux=20 (2.4.20).
Wenn i install 150 Input-Chains like=20 this:
iptables -A input -s = 192.168.81.xxx
i will lose a lot of perfomance (for = example:=20 apache take a lot of time, ssh ...)
Wenn i show the perfomance with vmstat = - vmstat=20 says that 99 % is idel...
Wer is the Problem ???
 
Thanks for helping ...=20 Michael
------=_NextPart_000_007A_01C31976.C0A8A920-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ralf Spenneberg Subject: Re: Performance losings with iptables Date: 20 May 2003 09:50:01 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <1053417001.1964.86.camel@kermit.spenneberg.de> References: <007d01c31965$fe099ce0$3a51a8c0@memmingen> Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <007d01c31965$fe099ce0$3a51a8c0@memmingen> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="iso-8859-1" To: Michael Albrecht Cc: Netfilter Am Die, 2003-05-13 um 17.40 schrieb Michael Albrecht: > Hello, > i use iptables with Debian-Linux (2.4.20). > Wenn i install 150 Input-Chains like this: > iptables -A input -s 192.168.81.xxx > i will lose a lot of perfomance (for example: apache take a lot of time, = ssh ...) > Wenn i show the perfomance with vmstat - vmstat says that 99 % is idel... > Wer is the Problem ??? I doubt that iptables itself is responsible for the performance loss. I rather suspect name resolution. Can you post you rules or at least some timing information? Cheers, Ralf --=20 Ralf Spenneberg RHCE, RHCX Book: Intrusion Detection f=FCr Linux Server http://www.spenneberg.com IPsec-Howto http://www.ipsec-howto.org Honeynet Project Mirror: =20 http://honeynet.spenneberg.org From mboxrd@z Thu Jan 1 00:00:00 1970 From: Julian Gomez Subject: Re: Performance losings with iptables Date: Tue, 20 May 2003 18:09:26 +0800 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20030520100926.GA1209@floyd> References: <007d01c31965$fe099ce0$3a51a8c0@memmingen> <1053417001.1964.86.camel@kermit.spenneberg.de> Reply-To: kluivert@tm.net.my Mime-Version: 1.0 Return-path: Content-Disposition: inline In-Reply-To: <1053417001.1964.86.camel@kermit.spenneberg.de> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Netfilter On Tue, May 20, 2003 at 09:50:01AM +0200, Ralf Spenneberg spoke thusly: >Am Die, 2003-05-13 um 17.40 schrieb Michael Albrecht: >> iptables -A input -s 192.168.81.xxx >> i will lose a lot of perfomance (for >> example: apache take a lot of time, ssh ...) Wenn i show the perfomance >> with vmstat - vmstat says that 99 % is As Michael has already mentioned, I too doubt its an iptables fault. I've had in excess of 1,300 rules running on a production firewall, for dynamic dumping of Nimda infected hosts. Its almost certainly a name resolving issue as Michael has already pointed to.