LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Server (http://www.linuxquestions.org/questions/linux-server-73/)
-   -   Best guess on how iptables will perform with thousands of rules? (http://www.linuxquestions.org/questions/linux-server-73/best-guess-on-how-iptables-will-perform-with-thousands-of-rules-920392/)

nyheat 12-24-2011 05:29 PM

Best guess on how iptables will perform with thousands of rules?
 
Anyone have experience with very large rulesets?

My current iptables ruleset forwards several hundred IP ranges to a different port.
But that ruleset is about to increase into the thousands and with time will grow into the tens of thousands.

I don't want to optimize prematurely, but I'm hesitant to add several thousand ranges without knowing what kind of impact it will have.

Does anyone have experience in this area, or can suggest some means of benchmarking the performance impact?

---

Sidenote: aside from the port forwarding for the aforementioned ranges, there are no other rules except for a handful of ACCEPTs.

* running Debian 6 with a 2.6.39 kernel.

d3vrandom 12-24-2011 07:18 PM

Use something like ipset:

http://ipset.netfilter.org/

fukawi1 12-24-2011 07:48 PM

May also be of some interest..

http://people.netfilter.org/kadlec/nftest.pdf


All times are GMT -5. The time now is 09:10 PM.