Linux Netfilter discussions
 help / color / mirror / Atom feed
* Completely DROP for UDP packets.
@ 2007-12-08 19:39 msn
  2007-12-08 20:34 ` Martijn Lievaart
  0 siblings, 1 reply; 5+ messages in thread
From: msn @ 2007-12-08 19:39 UTC (permalink / raw)
  To: netfilter

Hi, I'm trying to dropping all UDP packets from specific address
but it still has higher CPU usages. anyone has ideas for this
issues ? here's example

A   --+--->  F
B   --+
C   --+

A/B/C sending massive UDP packets to F, also it has address dropping
rules fro A/B/C. Yes, it is works fine. But if i see the CPU usages
of 'F' some of cases it is using more than 20-30% when its(A/B/C)
sending 100M to F. is there any best way to decreasing the CPU usage
of the 'F' ? thanks in advance.

Cheers.

P.S :
1. INPUT filter dropping very higher CPU usages
2. TARPIT and prestate PREROUTING dropping less higher but not satisfied.




^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2007-12-10 15:17 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-12-08 19:39 Completely DROP for UDP packets msn
2007-12-08 20:34 ` Martijn Lievaart
2007-12-10  5:43   ` msn
2007-12-10  5:45   ` msn
2007-12-10 15:17     ` Pascal Hambourg

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox