[prev in list] [next in list] [prev in thread] [next in thread] 

List:       freebsd-hackers
Subject:    Re: Throughput extremely decreases when IPFW 7000 mac based rules activated
From:       "Andrey V. Elsukov" <bu7cher () yandex ! ru>
Date:       2021-08-16 13:57:36
Message-ID: 2f5f9f6e-27da-1d4a-e462-93ef12f84d33 () yandex ! ru
[Download RAW message or body]

[Attachment #2 (multipart/mixed)]


10.08.2021 08:08, Eugene Grosbein пишет:
> Such ruleset could decrease filtering overhead several times but I'm
> afraid that ipfw is not right tool for this task at the moment.
> 
> ipfw has "tables" to optimize large list matching and they perform
> great but for layer3 IP matching, not for layer2 MAC matching.

We have a patch that adds ability to keep MAC addresses in the tables. I
hope we will push it into upstreem soon.

-- 
WBR, Andrey V. Elsukov


["OpenPGP_signature.asc" (application/pgp-signature)]

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic