Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 16 Aug 2021 16:57:36 +0300
From:      "Andrey V. Elsukov" <bu7cher@yandex.ru>
To:        Eugene Grosbein <eugen@grosbein.net>, alfadev <alfadev@protonmail.com>, "freebsd-hackers@FreeBSD.org" <freebsd-hackers@FreeBSD.org>, "freebsd-ipfw@FreeBSD.org" <freebsd-ipfw@FreeBSD.org>, "Alexander V. Chernikov" <melifaro@freebsd.org>
Subject:   Re: Throughput extremely decreases when IPFW 7000 mac based rules activated
Message-ID:  <2f5f9f6e-27da-1d4a-e462-93ef12f84d33@yandex.ru>
In-Reply-To: <7a737f3d-e291-e8a1-b629-09365a99c937@grosbein.net>
References:  <l4X4keiunQJV31eCpFqdbMySwywRGiWBB6PkAZ-xXmxy8rIfGVD_OVYCPi_X8YfmlMwslbRI3VcS4S9jkvmBS62PwFzMizEwIwwxxXD9FlQ=@protonmail.com> <7a737f3d-e291-e8a1-b629-09365a99c937@grosbein.net>

next in thread | previous in thread | raw e-mail | index | archive | help
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--wbct9JzOgqnVweG2vEHvgb1NQueBvX6kw
Content-Type: multipart/mixed; boundary="nrBYf2gus7xPntRhO5VGfCPpYsJREMn9z";
 protected-headers="v1"
From: "Andrey V. Elsukov" <bu7cher@yandex.ru>
To: Eugene Grosbein <eugen@grosbein.net>, alfadev <alfadev@protonmail.com>,
 "freebsd-hackers@FreeBSD.org" <freebsd-hackers@FreeBSD.org>,
 "freebsd-ipfw@FreeBSD.org" <freebsd-ipfw@FreeBSD.org>,
 "Alexander V. Chernikov" <melifaro@freebsd.org>
Message-ID: <2f5f9f6e-27da-1d4a-e462-93ef12f84d33@yandex.ru>
Subject: Re: Throughput extremely decreases when IPFW 7000 mac based rules
 activated
References: <l4X4keiunQJV31eCpFqdbMySwywRGiWBB6PkAZ-xXmxy8rIfGVD_OVYCPi_X8YfmlMwslbRI3VcS4S9jkvmBS62PwFzMizEwIwwxxXD9FlQ=@protonmail.com>
 <7a737f3d-e291-e8a1-b629-09365a99c937@grosbein.net>
In-Reply-To: <7a737f3d-e291-e8a1-b629-09365a99c937@grosbein.net>

--nrBYf2gus7xPntRhO5VGfCPpYsJREMn9z
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable

10.08.2021 08:08, Eugene Grosbein =D0=BF=D0=B8=D1=88=D0=B5=D1=82:
> Such ruleset could decrease filtering overhead several times but I'm
> afraid that ipfw is not right tool for this task at the moment.
>=20
> ipfw has "tables" to optimize large list matching and they perform
> great but for layer3 IP matching, not for layer2 MAC matching.

We have a patch that adds ability to keep MAC addresses in the tables. I
hope we will push it into upstreem soon.

--=20
WBR, Andrey V. Elsukov


--nrBYf2gus7xPntRhO5VGfCPpYsJREMn9z--

--wbct9JzOgqnVweG2vEHvgb1NQueBvX6kw
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEE5lkeG0HaFRbwybwAAcXqBBDIoXoFAmEabtAFAwAAAAAACgkQAcXqBBDIoXq2
TQgAsQK2y8hlwBojnQ25ibtxtbhFcaXOZRsCVJ9mgMNfsHyjG0LlSLR38wF851I7fPUf7gI+3tWt
j9UbNVdxnSwFRvdhu9leXS7RUfDo4GhwCoFt8KSbtSvi9AlOMqiXgMolE1CY/0lD9JfHvMa2VnFN
eiTX+0hPbt8t+T6lnXg+Az0h0h/OtDEodDNIy1PPKteGAfng+kG8cOVulLeLsk+KLPlM6SMfGw3p
OO+F2aM8A0sl+KIrRdc86vUbQ54lrmeNBG0OS51k9Vx+QVWxUcPN04EeRFgU7Q2JWRwsgFLhZrHL
GVqTar55rFf+2IB4h6MrJXOE6UxMj90Ie/e8veCDNw==
=EX5L
-----END PGP SIGNATURE-----

--wbct9JzOgqnVweG2vEHvgb1NQueBvX6kw--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?2f5f9f6e-27da-1d4a-e462-93ef12f84d33>