Linux Netfilter discussions
 help / color / mirror / Atom feed
From: <tsh@mrc-lmb.cam.ac.uk>
To: Chris Wilson <chris@netservers.co.uk>
Cc: netfilter@lists.netfilter.org
Subject: Re: Interesting problems
Date: Tue, 5 Aug 2003 11:34:41 +0100 (BST)	[thread overview]
Message-ID: <200308051034.LAA447988@alf1.lmb.internal> (raw)
In-Reply-To: <Pine.LNX.4.44.0308051025320.21531-100000@localhost> from Chris Wilson at "Aug 5, 2003 10:38:13 am"

>For reference, we have a 350MHz Cyrix machine handling iptables with
>stateful inspection for a medium-loaded 2Mb line with maybe 50 users/boxes
>behind it, and it has about 3000 connections right now and a load of 0.04.
>50% of CPU time is used by the System, indicating netfilter.  Perhaps your
>users are very busy?

Chris, I'm interested in why your 50 users generate 3000 connections.
We have about 1200 machines behind a stateful iptables box which has a 1GHz
cpu with 128Mb mem. Of these 1200, probably < two-thirds ever connect
to the outside world, (e.g. right now wc -l '/proc/net/ip_conntrack'
shows 1221 entries). I had no idea how to estimate the potential
load on such a box, but this box also does NAT and some routing
(we're gradually moving ourselves to private ip space) and I've
never seen it even blink in terms of load. I run an idle process
(a loopstop) at 'nice' 19, and top always shows this at 99% cpu.
We have a 100Mb link to Janet and regularly achieve wire-speed
transfers for things like ftp between us and fast nearby sites,
and again, cpu-load is essentially zero during these.

I realise that different iptables activities will present different
cpu loads (packet rate, number of entries in the tables, number of
active connections etc) but do you have any feel for which of these
is the most costly?

Cheers,
Terry



Terry Horsnell (tsh@mrc-lmb.cam.ac.uk)
I.T. Manager
Medical Research Council
Lab of Molecular Biology
Hills Road
CAMBRIDGE CB2 2QH
U.K.
Phone:	+44 (0)1223 248011
Fax:	+44 (0)1223 213556



  reply	other threads:[~2003-08-05 10:34 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-08-04 20:41 Interesting problems Peteris Krumins
2003-08-05  9:38 ` Chris Wilson
2003-08-05 10:34   ` tsh [this message]
2003-08-05 11:00     ` Chris Wilson
2003-08-05 19:54   ` Re[2]: " Peteris Krumins
2003-08-06 10:03     ` Chris Wilson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200308051034.LAA447988@alf1.lmb.internal \
    --to=tsh@mrc-lmb.cam.ac.uk \
    --cc=chris@netservers.co.uk \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox