Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Taylor, Grant" <gtaylor@riverviewtech.net>
To: netfilter@lists.netfilter.org
Subject: Re: Linux forwarding Win XP hosts VERY slowly
Date: Sat, 30 Apr 2005 18:06:57 -0500	[thread overview]
Message-ID: <42740F91.8020101@riverviewtech.net> (raw)
In-Reply-To: <200504301341.58023.dcinege-mlists@psychosis.com>

> I've built an advanced rotuign appliance, and I'm having 2 outstanding 
> problems, that I'm being to think are related to the linux ip/netfilter 
> stack, choking on XP traffic (possiblity XP-SP2) hosts that are on the LAN. 
> I'm running 2.4.30 at the moment. 
> 
> The 2 problems I'm seeing:
> 
> 1) Forwarded traffic (most notably web) is VERY slow with XP clients. 
> 
> Example: Saw this last 2 nights ago: Appliance has a linksys Wifi bridge 
> attached to a NIC. Customer browses through the appliance to the Linksys 
> config page. It moves like molasses. He browse to the local Zope hosted made 
> page. Slow as hell. I unplug his machine, and plug my linux laptop into same 
> switch port. Linksys and Zope pages load adn reload instantly. Plug his 
> machine in....slow again.
> 
> 2) Zope serves user interface pages for the appliance. Zope has been locking 
> solid for no apparent reason, but only when and Windows host is attached. 
> The trick is SOME windows machine don't seem to cause a problem.
> Example: 
> I worked with a unit for 3 days using a customers XP desktop. Not a hiccup. My 
> partner came in and attached to the network and starting connect to our 
> appliance with his XP laptop. Within 15 minutes Zope was hung. 
> 
> I'm really lost. ANY ideas out there?

I don't know if this is related or not, but a couple of this come to mind.

  1)  Check to make sure that it is not a ""windowing issue, i.e. the MTU/MRU, MSS, etc.
  2)  I know that XP SP 2 changes the number of TCP/IP connections that a computer can have open at any given time.  I think the default prior to XP SP 2 was 50 or there abouts.  Now the default for XP SP 2 is 10, or so I have read.  Apparently this is a registry (?) setting that can be changed.  From what I have read is that this was / is an effort by M$ to make sure that infected systems can only infect other systems at a controlled rate.  This problem has primarily shown up on VoIP mailing lists as VoIP needs LOTS of small packets at any given time exceeding the amount that XP SP 2 will allow by default.



Grant. . . .


  reply	other threads:[~2005-04-30 23:06 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-04-30 17:41 Linux forwarding Win XP hosts VERY slowly Dave Cinege
2005-04-30 23:06 ` Taylor, Grant [this message]
2005-05-01  4:10 ` Alistair Tonner
2005-05-02  7:07 ` Raphael Jacquot
2005-05-02  7:14   ` Taylor, Grant
  -- strict thread matches above, loose matches on Subject: below --
2005-05-01 12:27 itd.nam
2005-05-02  0:52 Dave Cinege
2005-05-02 17:20 Dave Cinege
2005-05-02 17:50 Dave Cinege
2005-05-02 20:03 ` Taylor, Grant
2005-05-02 20:47 ` Mogens Valentin
2005-05-02 21:29 Dave Cinege

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=42740F91.8020101@riverviewtech.net \
    --to=gtaylor@riverviewtech.net \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox