1 |
Can you expand a bit? Do you mean no iptables to running some rules, or |
2 |
a few rules to a lot of rules, or general wildcards (e.g. CC) compared |
3 |
to individual targets? |
4 |
|
5 |
I have noticed a slight increase with > 2000 rules, but its quite |
6 |
noticeable >6000 rules (adds a ~200ms or so to latency) |
7 |
|
8 |
* why so many rules: one of the kids ran a downloader program that |
9 |
included bittorrent and the drop script happily blackholed each connect |
10 |
with an individual rule. I only discovered it by accident (checking the |
11 |
logs) - everything was ticking over quite nicely! |
12 |
|
13 |
BillK |
14 |
|
15 |
On Sat, 2005-10-08 at 04:23 +0000, Luke-Jr wrote: |
16 |
> On Thursday 06 October 2005 00:15, Mark Rudholm wrote: |
17 |
> > route add bad.person.or.network 127.0.0.1 (or otherwise bogus destination) |
18 |
> > is an effective emergency block. |
19 |
> |
20 |
> Just a small note: I've found that using iptables to drop the packets affects |
21 |
> latency quite a bit ;) |
22 |
> |
23 |
-- |
24 |
William Kenworthy <billk@×××××××××.au> |
25 |
Home! |
26 |
-- |
27 |
gentoo-server@g.o mailing list |