From: "Harrison, James" <james.harrison@americancolor.com>
To: netfilter@lists.netfilter.org
Subject: Troubleshooting Netfilter Firewall (performance issues)
Date: Thu, 03 Nov 2005 11:28:03 -0600 [thread overview]
Message-ID: <1131038884.3835.11.camel@localhost.localdomain> (raw)
List,
I am currently troubleshooting performance issues on a network that seem
to indicate an issue with the firewall.
I've been using a netfilter configuration for almost 2 years without
issue, but we have been suffering through lost connections(tcp resets)
when transferring files through the firewall via scp, ftp, http, and
smb.
All interfaces on the firewall and on the switches connected to the
firewall appear clean.
Can someone help me troubleshoot this to determine what might be going
on? I've used fwbuilder to build the ruleset and up until ~10/7/2005 we
were not experiencing any issues whatsoever.
The current box is a dual processor(1400Mhz) Dell 1650:
top says:
top - 11:26:42 up 9 days, 10:21, 3 users, load average: 0.05, 0.06, 0.06
Tasks: 51 total, 1 running, 50 sleeping, 0 stopped, 0 zombie
Cpu(s): 0.0% user, 1.0% system, 0.0% nice, 99.0% idle
Mem: 1032992k total, 124124k used, 908868k free, 9744k buffers
Swap: 0k total, 0k used, 0k free, 28660k cached
netstat -s says:
Ip:
803083052 total packets received
797709786 forwarded
0 incoming packets discarded
1206740 incoming packets delivered
2326772 requests sent out
1008 outgoing packets dropped
11 fragments dropped after timeout
222078 reassemblies required
11467 packets reassembled ok
11 packet reassembles failed
11184 fragments received ok
221228 fragments created
Icmp:
45 ICMP messages received
10 input ICMP message failed.
ICMP input histogram:
destination unreachable: 2
echo requests: 33
13281 ICMP messages sent
0 ICMP messages failed
ICMP output histogram:
destination unreachable: 1610
time exceeded: 11671
Tcp:
4 active connections openings
114 passive connection openings
2 failed connection attempts
12 connection resets received
3 connections established
382150 segments received
834405 segments send out
10239 segments retransmited
0 bad segments received.
330 resets sent
Udp:
819564 packets received
319 packets to unknown port received.
0 packet receive errors
1479565 packets sent
TcpExt:
58 invalid SYN cookies received
29 TCP sockets finished time wait in fast timer
7 packets rejects in established connections because of timestamp
576 delayed acks sent
27 delayed acks further delayed because of locked socket
Quick ack mode was activated 58 times
181 packets directly queued to recvmsg prequeue.
193 of bytes directly received from prequeue
10144 packet headers predicted
4 packets header predicted and directly queued to user
56472 acknowledgments not containing data received
302400 predicted acknowledgments
170 times recovered from packet loss due to SACK data
Detected reordering 6 times using time stamp
4 congestion windows fully recovered
82 congestion windows partially recovered using Hoe heuristic
TCPDSACKUndo: 1
1035 congestion windows recovered after partial ack
88 TCP data loss events
27 timeouts after SACK recovery
374 fast retransmits
29 forward retransmits
8106 retransmits in slow start
1610 other TCP timeouts
5 sack retransmits failed
58 DSACKs sent for old packets
3003 DSACKs received
5 DSACKs for out of order packets received
6 connections aborted due to timeout
Thanks
--
James Harrison RHCE
Manager, Information Security
AIM: harrijh1
next reply other threads:[~2005-11-03 17:28 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-11-03 17:28 Harrison, James [this message]
-- strict thread matches above, loose matches on Subject: below --
2005-11-03 17:55 Troubleshooting Netfilter Firewall (performance issues) Derick Anderson
2005-11-03 18:24 ` Harrison, James
2005-11-04 14:42 Derick Anderson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1131038884.3835.11.camel@localhost.localdomain \
--to=james.harrison@americancolor.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox