Linux Netfilter discussions
 help / color / mirror / Atom feed
* How Expensive?
@ 2010-07-28  0:23 Jonathan Tripathy
  2010-07-28  1:17 ` Payam Chychi
  0 siblings, 1 reply; 4+ messages in thread
From: Jonathan Tripathy @ 2010-07-28  0:23 UTC (permalink / raw)
  To: netfilter

Hi Everyone,

I wish to use iptables on a host that will be hosting a large number of 
VMs for customers. IPtables will do some basic "managed firewalling" for 
them.

My question is, how expensive are having lots of custom chains? My idea 
is to create one child chain per VM, with the idea to cut down the 
amount of rules evaluated (i.e. a parent chain would only jump to a 
child chain if the dest IP matches) - does this sound like a good idea?

Thanks

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2010-07-28  7:41 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-07-28  0:23 How Expensive? Jonathan Tripathy
2010-07-28  1:17 ` Payam Chychi
2010-07-28  6:12   ` Jan Engelhardt
2010-07-28  7:41     ` Payam Chychi

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox