Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Radek Kanovsky <rk@dat.cz>
To: Jan Engelhardt <jengelh@medozas.de>
Cc: netfilter@vger.kernel.org
Subject: Re: iptables rules in comparable form
Date: Tue, 1 Jun 2010 18:03:37 +0200	[thread overview]
Message-ID: <20100601160337.GB15745@q.uh.cz> (raw)
In-Reply-To: <alpine.LSU.2.01.1006011353310.22291@obet.zrqbmnf.qr>

On Tue, Jun 01, 2010 at 01:56:37PM +0200, Jan Engelhardt wrote:

> >Whole iptables ruleset is represented by few files in /etc. Some of them
> >are generated, some of them are hand written. I am able to feed /etc
> >rules to iptables-restore or execute them as shell script. This is
> >trivial. Although iptables-restore is faster than executing iptables in
> >shell script, it is still very slow sometimes.
> >
> >Changes in /etc ruleset are small but frequent. But primarily both
> >solutions reset couters if used and it is not good for me now. So I
> >ended with script that does incremental updates.
> 
> How slow are we talking about? restore is never slower than
> iptables - ever, because, like iptables, it does one table replace
> operation per invocation of either binary. Your "incremental update"
> is in fact none, because tables are always replaced wholesome.

I know that iptables-restore with 10000 rules on input is faster than
10000 sequential "iptables -A ..." rules. It is obvious. But anyway it
is sometimes slower than my one "iptables -D" command followed by one
"iptables -A" command that both together reflect one particular change
in ruleset that I am able to recognize with rule comparison. Especially
under higher load. Reason is not obvious. I was forced also implement my
own locking and memoization around iptables-save that prevents its
concurrent invocation from accounting process. The accounting is simple -
it transfers output to accounting machinge. That caused troubles in the
past when I used to see hanging iptables-save/-restore processes. Maybe
some locking issues? It is hard to reproduce or debug for me. We use
Debian Etch and Lenny mainly without any kernel or netfilter customization.

I wanted to discuss this theme before I will start to prepare incremental
updates for tc configuration. It is even worse as restart takes routinely
1 or 2 minutes and there is no tc-restore mechanism and tc output
is totally different from its input.

Also note that my problem is not performance of packet filtering.
It is OK.

Regards

Radek Kanovsky

  reply	other threads:[~2010-06-01 16:03 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-06-01  8:10 iptables rules in comparable form Radek Kanovsky
2010-06-01  8:50 ` Jan Engelhardt
2010-06-01  9:18   ` Mart Frauenlob
2010-06-01 11:25     ` Radek Kanovsky
2010-06-01 11:56       ` Jan Engelhardt
2010-06-01 16:03         ` Radek Kanovsky [this message]
2010-06-01 18:19           ` Jan Engelhardt
2010-06-01 18:35             ` Radek Kanovsky
2010-06-01 18:01         ` Radek Kanovsky
2010-06-01 18:26           ` Jan Engelhardt
2010-06-01 19:36             ` Radek Kanovsky
2010-06-01 20:29               ` Pieter Smit
2010-06-02  6:17                 ` Radek Kanovsky
2010-06-01 13:27       ` Mart Frauenlob
2010-06-01 16:47         ` Radek Kanovsky

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20100601160337.GB15745@q.uh.cz \
    --to=rk@dat.cz \
    --cc=jengelh@medozas.de \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox