Linux Netfilter discussions
 help / color / mirror / Atom feed
* ipables and caching
@ 2012-01-24 14:28 Alex Bligh
  2012-01-24 16:29 ` Jan Engelhardt
  0 siblings, 1 reply; 5+ messages in thread
From: Alex Bligh @ 2012-01-24 14:28 UTC (permalink / raw)
  To: Mail List - Netfilter; +Cc: Alex Bligh

I have a legacy application which forwards lots of packets (router,
essentially) and uses a lot of sometimes badly written autogenerated
iptables rules (about 3,000 of them).

I am seeing on a good day high route cache efficiency. Do packets
which do not follow the slow path (i.e. cache hits) also cache
what iptables rules they hit? Nothing fancy in use bar conn_track.
If not, is there some magic wand I can use (other than a rewrite,
which has already been done but can't be used in some circumstances)
to speed up rule processing?

-- 
Alex Bligh

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2012-01-30  0:00 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-01-24 14:28 ipables and caching Alex Bligh
2012-01-24 16:29 ` Jan Engelhardt
2012-01-27 13:11   ` Alex Bligh
2012-01-29 23:28     ` Ed W
2012-01-30  0:00     ` Jan Engelhardt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox