From owner-freebsd-ipfw@FreeBSD.ORG Mon Nov 10 07:58:58 2003 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id DBD2416A4CF for ; Mon, 10 Nov 2003 07:58:58 -0800 (PST) Received: from tenebras.com (dnscache.tenebras.com [66.92.188.165]) by mx1.FreeBSD.org (Postfix) with SMTP id 919F943FB1 for ; Mon, 10 Nov 2003 07:58:57 -0800 (PST) (envelope-from kudzu@tenebras.com) Received: (qmail 65584 invoked from network); 10 Nov 2003 15:58:57 -0000 Received: from sapphire.tenebras.com (HELO tenebras.com) (192.168.188.241) by laptop.tenebras.com with SMTP; 10 Nov 2003 15:58:57 -0000 Message-ID: <3FAFB5C0.6070509@tenebras.com> Date: Mon, 10 Nov 2003 07:58:56 -0800 From: Michael Sierchio User-Agent: Mozilla/5.0 (X11; U; Linux i386; en-US; rv:1.5) Gecko/20031007 X-Accept-Language: en-us, zh-tw, zh-cn, fr, en, de-de MIME-Version: 1.0 To: freebsd-ipfw@freebsd.org References: <20031110080053.5A99543F3F@mx1.FreeBSD.org> In-Reply-To: <20031110080053.5A99543F3F@mx1.FreeBSD.org> Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: loading lot of rules takes very long time X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 10 Nov 2003 15:58:59 -0000 Artis Caune wrote: > So I belive our rules design is not ok, but we can > do nothing about it! Because you need the eggs? > ipfw need about 25-35min to load 30000 rules. 30000? I'm suspicious of any ruleset with more than 300. I suppose if this is just an academic exercise, have fun.