From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Travis Crook" Subject: Speed Issues through NAT Firewall Date: Tue, 9 Jul 2002 11:29:49 -0600 Sender: netfilter-admin@lists.samba.org Message-ID: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0014_01C2273B.EFAF6C00" Return-path: Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.samba.org This is a multi-part message in MIME format. ------=_NextPart_000_0014_01C2273B.EFAF6C00 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hello, I currently have two firewalls running. Both on Mandrake 8.1 = running iptables. I currently have two internet connections (one is a = DSL line at 1Mb, the other is straight from an ISP at 2.5 Mb). I can = get 700Kb speeds through the firewall on the DSL line (which is about as = fast as it ever is) but I only get about 500Kb speeds through the = firewall on the ISP line. Shouldn't I be able to get at least 2Mb = speeds through this firewall?=20 Thanks Travis Crook Visions Beyond ------=_NextPart_000_0014_01C2273B.EFAF6C00 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Hello,
    I currently have two firewalls running.  = Both on=20 Mandrake 8.1 running iptables.  I currently have two internet = connections=20 (one is a DSL line at 1Mb, the other is straight from an ISP at 2.5 = Mb).  I=20 can get 700Kb speeds through the firewall on the DSL line (which is = about as=20 fast as it ever is) but I only get about 500Kb speeds through the = firewall on=20 the ISP line.  Shouldn't I be able to get at least 2Mb speeds = through this=20 firewall?
 
Thanks
 
Travis Crook
Visions Beyond
------=_NextPart_000_0014_01C2273B.EFAF6C00-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ramin Alidousti Subject: Re: Speed Issues through NAT Firewall Date: Tue, 9 Jul 2002 13:38:58 -0400 Sender: netfilter-admin@lists.samba.org Message-ID: <20020709173858.GY25368@cannon.eng.us.uu.net> References: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> Mime-Version: 1.0 Return-path: Content-Disposition: inline In-Reply-To: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Travis Crook Cc: netfilter@lists.samba.org On Tue, Jul 09, 2002 at 11:29:49AM -0600, Travis Crook wrote: > Hello, > I currently have two firewalls running. Both on Mandrake 8.1 running iptables. I currently have two internet connections (one is a DSL line at 1Mb, the other is straight from an ISP at 2.5 Mb). I can get 700Kb speeds through the firewall on the DSL line (which is about as fast as it ever is) but I only get about 500Kb speeds through the firewall on the ISP line. Shouldn't I be able to get at least 2Mb speeds through this firewall? How do you measure the throughput? Ramin PS. Line breaks are good things. > > Thanks > > Travis Crook > Visions Beyond From mboxrd@z Thu Jan 1 00:00:00 1970 From: Patrick Schaaf Subject: Re: Speed Issues through NAT Firewall Date: Tue, 9 Jul 2002 19:49:26 +0200 Sender: netfilter-admin@lists.samba.org Message-ID: <20020709194926.A17608@oknodo.bof.de> References: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> Mime-Version: 1.0 Return-path: Content-Disposition: inline In-Reply-To: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com>; from travis@visionsbeyond.com on Tue, Jul 09, 2002 at 11:29:49AM -0600 Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Travis Crook Cc: netfilter@lists.samba.org > I currently have two firewalls running. Both on Mandrake 8.1 running iptables. I currently have two internet connections (one is a DSL line at 1Mb, the other is straight from an ISP at 2.5 Mb). I can get 700Kb speeds through the firewall on the DSL line (which is about as fast as it ever is) but I only get about 500Kb speeds through the firewall on the ISP line. Shouldn't I be able to get at least 2Mb speeds through this firewall? At least you can be almost assured that your problems have nothing to do with iptables and it's NAT. Starting up my crystal ball, I predict you'll find some half/full duplex mismatch on one of your Ethernets. Oh, and what type and speed are your CPUs? best regards Patrick From mboxrd@z Thu Jan 1 00:00:00 1970 From: Antony Stone Subject: Re: Speed Issues through NAT Firewall Date: Tue, 9 Jul 2002 18:53:34 +0100 Sender: netfilter-admin@lists.samba.org Message-ID: <200207091753.g69Hre810110@vulcan.rissington.net> References: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> Mime-Version: 1.0 Content-Transfer-Encoding: 8bit Return-path: In-Reply-To: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.samba.org On Tuesday 09 July 2002 6:29 pm, Travis Crook wrote: > Hello, > I currently have two firewalls running. Both on Mandrake 8.1 running > iptables. I currently have two internet connections (one is a DSL line at > 1Mb, the other is straight from an ISP at 2.5 Mb). I can get 700Kb speeds > through the firewall on the DSL line (which is about as fast as it ever is) > but I only get about 500Kb speeds through the firewall on the ISP line. > Shouldn't I be able to get at least 2Mb speeds through this firewall? What's your hardware (CPU, RAM, NIC) ? How many connections do you have concurrently through the boxes ? Quick way to get a rough idea: wc -l /proc/net/ip_conntrack Antony. From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Travis Crook" Subject: Re: Speed Issues through NAT Firewall Date: Tue, 9 Jul 2002 11:57:41 -0600 Sender: netfilter-admin@lists.samba.org Message-ID: <005501c22772$1ef01240$6702a8c0@mindtrip.com> References: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> <20020709194926.A17608@oknodo.bof.de> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: Patrick Schaaf Cc: netfilter@lists.samba.org The firewall on the DSL is an Athlon XP 1500+. The firewall on the ISP line is a PII 333. I will check on the full/half duplex issue. Travis Crook Visions Beyond ----- Original Message ----- From: "Patrick Schaaf" To: "Travis Crook" Cc: Sent: Tuesday, July 09, 2002 11:49 AM Subject: Re: Speed Issues through NAT Firewall > > I currently have two firewalls running. Both on Mandrake 8.1 running iptables. I currently have two internet connections (one is a DSL line at 1Mb, the other is straight from an ISP at 2.5 Mb). I can get 700Kb speeds through the firewall on the DSL line (which is about as fast as it ever is) but I only get about 500Kb speeds through the firewall on the ISP line. Shouldn't I be able to get at least 2Mb speeds through this firewall? > > At least you can be almost assured that your problems have nothing to > do with iptables and it's NAT. Starting up my crystal ball, I predict > you'll find some half/full duplex mismatch on one of your Ethernets. > Oh, and what type and speed are your CPUs? > > best regards > Patrick > From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Travis Crook" Subject: Re: Speed Issues through NAT Firewall Date: Tue, 9 Jul 2002 11:59:56 -0600 Sender: netfilter-admin@lists.samba.org Message-ID: <006801c22772$6faa9340$6702a8c0@mindtrip.com> References: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> <20020709173858.GY25368@cannon.eng.us.uu.net> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: Ramin Alidousti Cc: netfilter@lists.samba.org > Hello, > I currently have two firewalls running. Both on Mandrake 8.1 running iptables. I currently have two internet connections (one is a DSL line at 1Mb, the other is straight from an ISP at 2.5 Mb). I can get 700Kb speeds through the firewall on the DSL line (which is about as fast as it ever is) but I only get about 500Kb speeds through the firewall on the ISP line. Shouldn't I be able to get at least 2Mb speeds through this firewall? > > How do you measure the throughput? I used http://promos.mcafee.com/speedometer and http://www.dslreports.com. I can get 3Mb testing on the firewall itself but not on a machine behind the firewall. > Ramin > PS. Line breaks are good things. I'll use more linebreaks. Thanks! From mboxrd@z Thu Jan 1 00:00:00 1970 From: Antony Stone Subject: Re: Speed Issues through NAT Firewall Date: Tue, 9 Jul 2002 19:08:22 +0100 Sender: netfilter-admin@lists.samba.org Message-ID: <200207091808.g69I8R810149@vulcan.rissington.net> References: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> <20020709194926.A17608@oknodo.bof.de> <005501c22772$1ef01240$6702a8c0@mindtrip.com> Mime-Version: 1.0 Content-Transfer-Encoding: 8bit Return-path: In-Reply-To: <005501c22772$1ef01240$6702a8c0@mindtrip.com> Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.samba.org On Tuesday 09 July 2002 6:57 pm, Travis Crook wrote: > The firewall on the DSL is an Athlon XP 1500+. The firewall on the ISP > line is a PII 333. I will check on the full/half duplex issue. That's a hell of a difference, and could conceivably account for the bandwidth. I'd say it depends on how much RAM you have in the PII/333 and how many connections you're trying to support. Antony. From mboxrd@z Thu Jan 1 00:00:00 1970 From: Martin Josefsson Subject: Re: Speed Issues through NAT Firewall Date: 09 Jul 2002 20:25:45 +0200 Sender: netfilter-admin@lists.samba.org Message-ID: <1026239145.804.56.camel@tux> References: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> <20020709194926.A17608@oknodo.bof.de> <005501c22772$1ef01240$6702a8c0@mindtrip.com> <200207091808.g69I8R810149@vulcan.rissington.net> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <200207091808.g69I8R810149@vulcan.rissington.net> Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: Antony Stone Cc: Netfilter On Tue, 2002-07-09 at 20:08, Antony Stone wrote: > On Tuesday 09 July 2002 6:57 pm, Travis Crook wrote: > > > The firewall on the DSL is an Athlon XP 1500+. The firewall on the ISP > > line is a PII 333. I will check on the full/half duplex issue. > > That's a hell of a difference, and could conceivably account for the > bandwidth. I'd say it depends on how much RAM you have in the PII/333 and > how many connections you're trying to support. No way a pII 333 is to slow to handle 2Mbit/s, my old 486 can handle that easily. You would have to trash the conntrack hashtable with multiple attacks to even have a chance of getting it that slow. I also believe there's a duplex-mismatch somewhere, probably between the firewall and the internal network. -- /Martin Never argue with an idiot. They drag you down to their level, then beat you with experience. From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ramin Alidousti Subject: Re: Speed Issues through NAT Firewall Date: Tue, 9 Jul 2002 14:28:26 -0400 Sender: netfilter-admin@lists.samba.org Message-ID: <20020709182826.GZ25368@cannon.eng.us.uu.net> References: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> <20020709173858.GY25368@cannon.eng.us.uu.net> <006801c22772$6faa9340$6702a8c0@mindtrip.com> Mime-Version: 1.0 Return-path: Content-Disposition: inline In-Reply-To: <006801c22772$6faa9340$6702a8c0@mindtrip.com> Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Travis Crook Cc: Ramin Alidousti , netfilter@lists.samba.org On Tue, Jul 09, 2002 at 11:59:56AM -0600, Travis Crook wrote: > > Hello, > > I currently have two firewalls running. Both on Mandrake 8.1 running > iptables. I currently have two internet connections (one is a DSL line at > 1Mb, the other is straight from an ISP at 2.5 Mb). I can get 700Kb speeds > through the firewall on the DSL line (which is about as fast as it ever is) > but I only get about 500Kb speeds through the firewall on the ISP line. > Shouldn't I be able to get at least 2Mb speeds through this firewall? > > > > How do you measure the throughput? > > I used http://promos.mcafee.com/speedometer and http://www.dslreports.com. > I can get 3Mb testing on the firewall itself but not on a machine behind the > firewall. Haven't been able to check the second site but the first one sends you a file and measures the actual download time. Now, imagine what happens when there is congestion along the path. Your throughput would show a very low number while the actual problem does not have anything to do with you and/or your upstream router. The reason for your "ISP line" showing 500kb and the "DSL line" showing 700Kb is IMO irrelevant to the netfilter overhead/througput. However, the delta between the same test done (a) on the firewall (b) from behind the firewall might be an indication of how fast (or slow, for that matter) the firewall machine is forwarding the packets. Like Patrick has pointed out, first of all you need to make sure that your devices and the wiring is healthy, though. Ramin > > > Ramin > > PS. Line breaks are good things. > > I'll use more linebreaks. Thanks! From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ramin Alidousti Subject: Re: Speed Issues through NAT Firewall Date: Tue, 9 Jul 2002 14:49:42 -0400 Sender: netfilter-admin@lists.samba.org Message-ID: <20020709184942.GA25368@cannon.eng.us.uu.net> References: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> <20020709194926.A17608@oknodo.bof.de> <005501c22772$1ef01240$6702a8c0@mindtrip.com> <200207091808.g69I8R810149@vulcan.rissington.net> <1026239145.804.56.camel@tux> Mime-Version: 1.0 Return-path: Content-Disposition: inline In-Reply-To: <1026239145.804.56.camel@tux> Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Martin Josefsson Cc: Antony Stone , Netfilter On Tue, Jul 09, 2002 at 08:25:45PM +0200, Martin Josefsson wrote: > > > The firewall on the DSL is an Athlon XP 1500+. The firewall on the ISP > > > line is a PII 333. I will check on the full/half duplex issue. > > > > That's a hell of a difference, and could conceivably account for the > > bandwidth. I'd say it depends on how much RAM you have in the PII/333 and > > how many connections you're trying to support. > > No way a pII 333 is to slow to handle 2Mbit/s, my old 486 can handle > that easily. You would have to trash the conntrack hashtable with > multiple attacks to even have a chance of getting it that slow. > > I also believe there's a duplex-mismatch somewhere, probably between the > firewall and the internal network. In that case a simple ping flood across the suspicious link can help... Ramin > > -- > /Martin > > Never argue with an idiot. They drag you down to their level, then beat > you with experience. From mboxrd@z Thu Jan 1 00:00:00 1970 From: "j davis" Subject: Re: Speed Issues through NAT Firewall Date: Tue, 09 Jul 2002 19:03:26 +0000 Sender: netfilter-admin@lists.samba.org Message-ID: Mime-Version: 1.0 Return-path: Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; format=flowed; charset="us-ascii" Content-Transfer-Encoding: 7bit To: netfilter@lists.samba.org also...do mii-tool from the command line to see your duplex and you can use a program called bing to test through put between 2 interfaces. jd http://www.taproot.bz >From: Antony Stone >To: >Subject: Re: Speed Issues through NAT Firewall >Date: Tue, 9 Jul 2002 19:08:22 +0100 >MIME-Version: 1.0 >Received: from [198.186.203.85] by hotmail.com (3.2) with ESMTP id >MHotMailBEF47481004D40043251C6BACB559E280; Tue, 09 Jul 2002 11:20:56 -0700 >Received: from va.samba.org (localhost [127.0.0.1])by lists.samba.org >(Postfix) with ESMTPid A0731495C; Tue, 9 Jul 2002 11:20:47 -0700 (PDT) >Received: from vulcan.rissington.net (mail.rissington.net >[213.121.241.158])by lists.samba.org (Postfix) with ESMTP id 57318495Efor >; Tue, 9 Jul 2002 11:08:40 -0700 (PDT) >Received: from there (dhcp211 [192.168.192.211] (may be forged))by >vulcan.rissington.net (8.10.2/8.10.2) with SMTP id g69I8R810149for >; Tue, 9 Jul 2002 19:08:27 +0100 >From netfilter-admin@lists.samba.org Tue, 09 Jul 2002 11:21:44 -0700 >Delivered-To: netfilter@lists.samba.org >Message-Id: <200207091808.g69I8R810149@vulcan.rissington.net> >Organization: Software Solutions >X-Mailer: KMail [version 1.3.2] >References: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> ><20020709194926.A17608@oknodo.bof.de> ><005501c22772$1ef01240$6702a8c0@mindtrip.com> >In-Reply-To: <005501c22772$1ef01240$6702a8c0@mindtrip.com> >Sender: netfilter-admin@lists.samba.org >Errors-To: netfilter-admin@lists.samba.org >X-BeenThere: netfilter@lists.samba.org >X-Mailman-Version: 2.0.8 >Precedence: bulk >List-Help: >List-Post: >List-Subscribe: >, >List-Id: netfilter user discussion list >List-Unsubscribe: >, >List-Archive: > >On Tuesday 09 July 2002 6:57 pm, Travis Crook wrote: > > > The firewall on the DSL is an Athlon XP 1500+. The firewall on the ISP > > line is a PII 333. I will check on the full/half duplex issue. > >That's a hell of a difference, and could conceivably account for the >bandwidth. I'd say it depends on how much RAM you have in the PII/333 and >how many connections you're trying to support. > > > >Antony. > thanks, jd jd@taproot.bz http://www.taproot.bz thanks, jd jd@taproot.bz http://www.taproot.bz _________________________________________________________________ Chat with friends online, try MSN Messenger: http://messenger.msn.com From mboxrd@z Thu Jan 1 00:00:00 1970 From: Antony Stone Subject: Re: Speed Issues through NAT Firewall Date: Tue, 9 Jul 2002 20:32:30 +0100 Sender: netfilter-admin@lists.samba.org Message-ID: <20020709193231.DGDB19225.mta07-svc.ntlworld.com@there> References: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> <200207091808.g69I8R810149@vulcan.rissington.net> <1026239145.804.56.camel@tux> Mime-Version: 1.0 Content-Transfer-Encoding: 8bit Return-path: In-Reply-To: <1026239145.804.56.camel@tux> Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: Netfilter On Tuesday 09 July 2002 7:25 pm, Martin Josefsson wrote: > On Tue, 2002-07-09 at 20:08, Antony Stone wrote: > > On Tuesday 09 July 2002 6:57 pm, Travis Crook wrote: > > > The firewall on the DSL is an Athlon XP 1500+. The firewall on the ISP > > > line is a PII 333. I will check on the full/half duplex issue. > > > > That's a hell of a difference, and could conceivably account for the > > bandwidth. I'd say it depends on how much RAM you have in the PII/333 > > and how many connections you're trying to support. > > No way a pII 333 is to slow to handle 2Mbit/s, my old 486 can handle > that easily. You would have to trash the conntrack hashtable with > multiple attacks to even have a chance of getting it that slow. I only said it could *conceivably* account for the bandwidth limit - I didn't say it was likely. I agree with you that a 486 can easily exceed this performance, but it depends what Travis is doing with the system - last summer I saw netfilter boxes reduced to tens of kbits/sec bandwidth by Nimda and Code Red saturating the conntracking tables with half-open links. I agree with several people here that Travis should check the hardware first, and I would also recommend testing the bandwidth by doing several downloads simultaneously from sites with high-bandwidth links, as close (in hops) to his machine as possible. Antony. From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Travis Crook" Subject: Re: Speed Issues through NAT Firewall Date: Tue, 9 Jul 2002 17:08:57 -0600 Sender: netfilter-admin@lists.samba.org Message-ID: <000401c2279d$a6591580$6702a8c0@mindtrip.com> References: <001701c2276e$3a94a0a0$6702a8c0@mindtrip.com> <200207091808.g69I8R810149@vulcan.rissington.net> <1026239145.804.56.camel@tux> <20020709193231.DGDB19225.mta07-svc.ntlworld.com@there> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: Antony Stone Cc: netfilter@lists.samba.org > I agree with several people here that Travis should check the hardware first, > and I would also recommend testing the bandwidth by doing several downloads > simultaneously from sites with high-bandwidth links, as close (in hops) to > his machine as possible. > > Antony. I checked the hardware. Everything is running 100baseTx-FD (100 mb full duplex). I used several different workstations and found the problem. If I test with a Windows 98 box I get 500Kb. If I test with a Windows 2000 box I get 1Mb, if I test with a Linux box I get 3.5Mb. Windows must have some kind of internet throttling. Yet another reason to use Linux. Thanks Everyone for your help! Travis Crook Visions Beyond