netfilter.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Recommended hardware for iptables based firewall/router
@ 2014-11-02  3:51 Dennis Jacobfeuerborn
  2014-11-02 22:38 ` Neal Murphy
  0 siblings, 1 reply; 8+ messages in thread
From: Dennis Jacobfeuerborn @ 2014-11-02  3:51 UTC (permalink / raw)
  To: netfilter

Hi,
we recently bought an Uqbiquity EdgeRouter Pro but it seems the claims
about 2 Mio. pps that it should be able to handle are not real-world
numbers. We are running about 120mbit through this system and are
already seeing the two risc cores struggling with high softirq load and
packet drops.

So my question is what a good hardware base would look like for a linux
based firewall using iptables/conntrack/ipset. Do offload features help
or can't these be used because iptables needs to process the packets
anyway? I assume multiqueuing would be nice too.
The idea is to be able to actually process 1gbit of traffic i.e. handle
two gbit ports (WAN and LAN) at wire-speed.

Does anyone have any specific recommendations for NICs and maybe tips
for other bottlenecks to look out for?

Regards,
  Dennis

^ permalink raw reply	[flat|nested] 8+ messages in thread
* Re: Recommended hardware for iptables based firewall/router
@ 2014-11-09  5:15 Stig Thormodsrud
  2014-11-09 14:05 ` Dennis Jacobfeuerborn
  0 siblings, 1 reply; 8+ messages in thread
From: Stig Thormodsrud @ 2014-11-09  5:15 UTC (permalink / raw)
  To: netfilter

On 09.11.2014 01:49, Yucong Sun wrote:
> Dennis Jacobfeuerborn <dennisml@conversis.de>
>
> The EdgeRouter 's asic couldn't handle all use cases ,  Having some
> special rule will make it go to "offload" disabled mode.  You should
> research if that's the problem.

I'm a developer on this product.  I'd be interested in the test cases
that it couldn't handle.

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2014-11-09 14:52 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-11-02  3:51 Recommended hardware for iptables based firewall/router Dennis Jacobfeuerborn
2014-11-02 22:38 ` Neal Murphy
2014-11-09  0:40   ` Dennis Jacobfeuerborn
     [not found]     ` <CAJygYd07-y0bDSr8THXWjNEW-e1rK5ZhGiE8aeJ_jXYJpFiL2A@mail.gmail.com>
2014-11-09  0:49       ` Yucong Sun
2014-11-09  1:11         ` Dennis Jacobfeuerborn
  -- strict thread matches above, loose matches on Subject: below --
2014-11-09  5:15 Stig Thormodsrud
2014-11-09 14:05 ` Dennis Jacobfeuerborn
2014-11-09 14:52   ` Dennis Jacobfeuerborn

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).