Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Ramin Alidousti <ramin@cannon.eng.us.uu.net>
To: Travis Crook <travis@visionsbeyond.com>
Cc: Ramin Alidousti <ramin@cannon.eng.us.uu.net>, netfilter@lists.samba.org
Subject: Re: Speed Issues through NAT Firewall
Date: Tue, 9 Jul 2002 14:28:26 -0400	[thread overview]
Message-ID: <20020709182826.GZ25368@cannon.eng.us.uu.net> (raw)
In-Reply-To: <006801c22772$6faa9340$6702a8c0@mindtrip.com>

On Tue, Jul 09, 2002 at 11:59:56AM -0600, Travis Crook wrote:

>  > Hello,
>  >     I currently have two firewalls running.  Both on Mandrake 8.1 running
> iptables.  I currently have two internet connections (one is a DSL line at
> 1Mb, the other is straight from an ISP at 2.5 Mb).  I can get 700Kb speeds
> through the firewall on the DSL line (which is about as fast as it ever is)
> but I only get about 500Kb speeds through the firewall on the ISP line.
> Shouldn't I be able to get at least 2Mb speeds through this firewall?
> >
> > How do you measure the throughput?
> 
> I used http://promos.mcafee.com/speedometer and http://www.dslreports.com.
> I can get 3Mb testing on the firewall itself but not on a machine behind the
> firewall.

Haven't been able to check the second site but the first one sends you a
file and measures the actual download time. Now, imagine what happens when
there is congestion along the path. Your throughput would show a very low
number while the actual problem does not have anything to do with you and/or
your upstream router.

The reason for your "ISP line" showing 500kb and the "DSL line" showing 700Kb
is IMO irrelevant to the netfilter overhead/througput. However, the delta between
the same test done (a) on the firewall (b) from behind the firewall might
be an indication of how fast (or slow, for that matter) the firewall machine
is forwarding the packets.

Like Patrick has pointed out, first of all you need to make sure that your
devices and the wiring is healthy, though.

Ramin

> 
> > Ramin
> > PS. Line breaks are good things.
> 
> I'll use more linebreaks.  Thanks!


  reply	other threads:[~2002-07-09 18:28 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-07-09 17:29 Speed Issues through NAT Firewall Travis Crook
2002-07-09 17:38 ` Ramin Alidousti
2002-07-09 17:59   ` Travis Crook
2002-07-09 18:28     ` Ramin Alidousti [this message]
2002-07-09 17:49 ` Patrick Schaaf
2002-07-09 17:57   ` Travis Crook
2002-07-09 18:08     ` Antony Stone
2002-07-09 18:25       ` Martin Josefsson
2002-07-09 18:49         ` Ramin Alidousti
2002-07-09 19:32         ` Antony Stone
2002-07-09 23:08           ` Travis Crook
2002-07-09 17:53 ` Antony Stone
  -- strict thread matches above, loose matches on Subject: below --
2002-07-09 19:03 j davis

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20020709182826.GZ25368@cannon.eng.us.uu.net \
    --to=ramin@cannon.eng.us.uu.net \
    --cc=netfilter@lists.samba.org \
    --cc=travis@visionsbeyond.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox