From owner-freebsd-net@FreeBSD.ORG Wed Jul 2 10:31:16 2003 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5AAFC37B401 for ; Wed, 2 Jul 2003 10:31:16 -0700 (PDT) Received: from laptop.tenebras.com (laptop.tenebras.com [66.92.188.18]) by mx1.FreeBSD.org (Postfix) with SMTP id C493343F75 for ; Wed, 2 Jul 2003 10:31:15 -0700 (PDT) (envelope-from kudzu@tenebras.com) Received: (qmail 21033 invoked from network); 2 Jul 2003 17:31:15 -0000 Received: from sapphire.tenebras.com (HELO tenebras.com) (192.168.188.241) by 0 with SMTP; 2 Jul 2003 17:31:15 -0000 Message-ID: <3F0316DE.3040301@tenebras.com> Date: Wed, 02 Jul 2003 10:31:10 -0700 From: Michael Sierchio User-Agent: Mozilla/5.0 (X11; U; Linux i386; en-US; rv:1.3.1) Gecko/20030425 X-Accept-Language: en-us, zh-tw, zh-cn, fr, en, de-de MIME-Version: 1.0 To: freebsd-ipfw@FreeBSD.ORG, freebsd-net@FreeBSD.ORG Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Subject: Performance improvement for NAT in IPFIREWALL X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 02 Jul 2003 17:31:16 -0000 Currently, performance w/divert sockets and natd in ipfirewall on a compute-bound platform (ELAN-133MHz) shows ipfw+natd throughput to be 50% of that offered by ipfilter+ipnat. Is there anything that can be done to speed up either the performance of divert and natd? Alternatively, could network address translation be merged into ipfirewall? As we move from 1000BASE-TX to 10000BASE-TX, this will become more of an issue, even on 3GHz machines. Comments? Suggestions? Vision?