[prev in list] [next in list] [prev in thread] [next in thread]
List: freebsd-hackers
Subject: Re: Throughput extremely decreases when IPFW 7000 mac based rules activated
From: "Andrey V. Elsukov" <bu7cher () yandex ! ru>
Date: 2021-08-16 13:57:36
Message-ID: 2f5f9f6e-27da-1d4a-e462-93ef12f84d33 () yandex ! ru
[Download RAW message or body]
[Attachment #2 (multipart/mixed)]
10.08.2021 08:08, Eugene Grosbein пишет:
> Such ruleset could decrease filtering overhead several times but I'm
> afraid that ipfw is not right tool for this task at the moment.
>
> ipfw has "tables" to optimize large list matching and they perform
> great but for layer3 IP matching, not for layer2 MAC matching.
We have a patch that adds ability to keep MAC addresses in the tables. I
hope we will push it into upstreem soon.
--
WBR, Andrey V. Elsukov
["OpenPGP_signature.asc" (application/pgp-signature)]
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic