What is the capacity of iptables etc?
I am running a CentOS with iptables v1.3.5. I came across a problem: occasionally this CentOS disappeared from network(cannot ping or ssh from outside), but through its console I can ping anywhere. Looks like something wrong with iptables.
I have around 10000 connections through iptables. What is the maximum connection iptables can handle? Where can I find performance parameter of iptables? Thanks! |
Quote:
|
Quote:
|
I really don't want to put you off in your quest, just to point out the difficulties...
I suppose that even if someone does some benchmarking on different hardware, you may be able to say 'well, that hardware is roughly twice as fast as mine, so I can divide their numbers by two' or something, but... Unless you know whether it is cpu limited or memory limited (and the perf does suddenly crash as you run out of ram and start swapping, so while it may be unknown, in general, whether this has started happening in their tests, it may be the most important factor) guessing the scaling factor will probably be flawed. And given that you can write iptables rulesets that are dramatically less efficient in memory usage than others (particularly if you rush at iptables modules like a man who hasn't eaten for two weeks at an all-you-can-eat buffet...or maybe you have gone for logging everything), the closest that I can get is that the unknown unknown-nesss is not as clear to me as it might be. Another particular; if a lot of connections are from something like slow_loris, which deliberately sets out to burn up resources without making massive numbers of connections, you will be in a worse situation than if you just have lots of 'ordinary' connections, whether or not those ordinary connections are malevolent. On the other hand, if you have a box upstream that re-assembles connections, your situation may be much easier and you may not have to worry about that. |
All times are GMT -5. The time now is 07:04 AM. |