Linux Netfilter discussions
 help / color / mirror / Atom feed
* iptables limit --limit limitations
@ 2008-05-17  7:20 Payam Chychi
  2008-05-26 11:20 ` Jan Engelhardt
  0 siblings, 1 reply; 3+ messages in thread
From: Payam Chychi @ 2008-05-17  7:20 UTC (permalink / raw)
  To: netfilter

Hi,

Has anyone experienced any limitations when implementing the "limit
--limit $value/sec"  ? I can only get 1000 packets/sec with a value of
1000 or 10000  with a burst of 5. Ive been able to increase the
packets to almost 7500 packers/sec when using a value of 10000 with a
burst of 20.

Ive also tried increasing the HZ for High res timer on the kernel to
1000 and enabled dynamic ticks (thanks to kuzin)
any thoughts or ideas on this? I would greatly appreciate any feedback...

Thanks,
Payam

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: iptables limit --limit limitations
  2008-05-17  7:20 iptables limit --limit limitations Payam Chychi
@ 2008-05-26 11:20 ` Jan Engelhardt
  2008-05-31 18:33   ` Jesper Dangaard Brouer
  0 siblings, 1 reply; 3+ messages in thread
From: Jan Engelhardt @ 2008-05-26 11:20 UTC (permalink / raw)
  To: Payam Chychi; +Cc: netfilter

On Saturday 2008-05-17 09:20, Payam Chychi wrote:

>Hi,
>
>Has anyone experienced any limitations when implementing the "limit
>--limit $value/sec"  ? I can only get 1000 packets/sec with a value of
>1000 or 10000  with a burst of 5. Ive been able to increase the
>packets to almost 7500 packers/sec when using a value of 10000 with a
>burst of 20.
>
>Ive also tried increasing the HZ for High res timer on the kernel to
>1000 and enabled dynamic ticks (thanks to kuzin)
>any thoughts or ideas on this? I would greatly appreciate any feedback...


It is known that the algorithm in limit and hashlimit are not quite 
accurate. Though, we seem to be out of solutions, too.


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: iptables limit --limit limitations
  2008-05-26 11:20 ` Jan Engelhardt
@ 2008-05-31 18:33   ` Jesper Dangaard Brouer
  0 siblings, 0 replies; 3+ messages in thread
From: Jesper Dangaard Brouer @ 2008-05-31 18:33 UTC (permalink / raw)
  To: netfilter

Jan Engelhardt <jengelh <at> medozas.de> writes:

> It is known that the algorithm in limit and hashlimit are not quite 
> accurate. Though, we seem to be out of solutions, too.

Here is a paper on it here:
 http://people.netfilter.org/acidfu/papers/limit-tbf-analysis.pdf

I don't know if the solution proposed has been implemented (and accepted
upstream)???

Cheers,
 Jesper Brouer


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2008-05-31 18:33 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-05-17  7:20 iptables limit --limit limitations Payam Chychi
2008-05-26 11:20 ` Jan Engelhardt
2008-05-31 18:33   ` Jesper Dangaard Brouer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox