From owner-freebsd-questions@freebsd.org Tue Aug 24 22:41:06 2021 Return-Path: Delivered-To: freebsd-questions@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 50D08668544 for ; Tue, 24 Aug 2021 22:41:06 +0000 (UTC) (envelope-from 93ab.82.c3790001c0a009.a7149d89435098da7232c6934b54b1cc@email-od.com) Received: from s1-b515.socketlabs.email-od.com (s1-b515.socketlabs.email-od.com [142.0.181.21]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4GvPGT1fvbz4RS4 for ; Tue, 24 Aug 2021 22:41:05 +0000 (UTC) (envelope-from 93ab.82.c3790001c0a009.a7149d89435098da7232c6934b54b1cc@email-od.com) X-Thread-Info: OTNhYi4xMi5jMzc5MDAwMWMwYTAwOS5mcmVlYnNkLXF1ZXN0aW9ucz1mcmVlYnNkLm9yZw== Received: from r2.us-east-2.aws.in.socketlabs.com (r2.us-east-2.aws.in.socketlabs.com [142.0.189.2]) by mxh4.email-od.com with ESMTP(version=Tls12 cipher=Aes256 bits=256); Tue, 24 Aug 2021 18:40:55 -0400 Received: from oceanview.tundraware.com (oceanview.tundraware.com [45.55.60.57]) by r2.us-east-2.aws.in.socketlabs.com with ESMTP(version=Tls12 cipher=Aes256 bits=256); Tue, 24 Aug 2021 18:40:54 -0400 Received: from [192.168.0.2] (ozzie.tundraware.com [75.145.138.73]) (authenticated bits=0) by oceanview.tundraware.com (8.16.1/8.16.1) with ESMTPSA id 17OMegI9078842 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NO); Tue, 24 Aug 2021 17:40:42 -0500 (CDT) (envelope-from tundra@tundraware.com) Subject: Re: ipfw Table Organization To: Michael Sierchio , FreeBSD Mailing List References: <9e6cd8e2-a06e-468b-7245-d5ff13309763@tundraware.com> From: Tim Daneliuk Message-ID: <7b9a7c6a-fc0e-a605-6938-8b89c09e0336@tundraware.com> Date: Tue, 24 Aug 2021 17:40:37 -0500 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.11.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit X-Greylist: Sender succeeded SMTP AUTH, not delayed by milter-greylist-4.6.4 (oceanview.tundraware.com [45.55.60.57]); Tue, 24 Aug 2021 17:40:42 -0500 (CDT) X-TundraWare-MailScanner-Information: Please contact the ISP for more information X-TundraWare-MailScanner-ID: 17OMegI9078842 X-TundraWare-MailScanner: Found to be clean X-TundraWare-MailScanner-SpamCheck: not spam (whitelisted), SpamAssassin (not cached, score=-4.128, required 6, autolearn=not spam, ALL_TRUSTED -1.00, BAYES_00 -1.90, NICE_REPLY_A -1.30, TW_PF 0.08) X-TundraWare-MailScanner-From: tundra@tundraware.com X-Spam-Status: No X-Rspamd-Queue-Id: 4GvPGT1fvbz4RS4 X-Spamd-Bar: --- X-Spamd-Result: default: False [-3.70 / 15.00]; RCVD_VIA_SMTP_AUTH(0.00)[]; ARC_NA(0.00)[]; R_DKIM_ALLOW(-0.20)[tundraware.com:s=slkey,email-od.com:s=dkim]; MID_RHS_MATCH_FROM(0.00)[]; FROM_HAS_DN(0.00)[]; R_SPF_ALLOW(-0.20)[+ip4:142.0.176.0/20]; NEURAL_HAM_LONG(-1.00)[-1.000]; MIME_GOOD(-0.10)[text/plain]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; RCVD_COUNT_THREE(0.00)[4]; TO_MATCH_ENVRCPT_SOME(0.00)[]; TO_DN_ALL(0.00)[]; DKIM_TRACE(0.00)[tundraware.com:+,email-od.com:+]; RCPT_COUNT_TWO(0.00)[2]; RCVD_IN_DNSWL_NONE(0.00)[142.0.181.21:from,142.0.189.2:received]; NEURAL_HAM_SHORT(-1.00)[-1.000]; DMARC_POLICY_ALLOW(-0.50)[tundraware.com,reject]; FORGED_SENDER(0.30)[tundra@tundraware.com,93ab.82.c3790001c0a009.a7149d89435098da7232c6934b54b1cc@email-od.com]; MIME_TRACE(0.00)[0:+]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:53658, ipnet:142.0.180.0/22, country:US]; FROM_NEQ_ENVFROM(0.00)[tundra@tundraware.com,93ab.82.c3790001c0a009.a7149d89435098da7232c6934b54b1cc@email-od.com]; MAILMAN_DEST(0.00)[freebsd-questions]; DWL_DNSWL_NONE(0.00)[email-od.com:dkim] X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 24 Aug 2021 22:41:06 -0000 On 8/24/21 5:30 PM, Michael Sierchio wrote: > Do you really mean 100,000 firewall rules? 100,000 CIDR blocks is not > a problem. You should probably consolidate CIDR blocks before adding them > to a > table, because it's a longest-prefix-match. Most of the 100,000 are CIDR blocks but there are probably on the order of 5000-ish IPs -- ---------------------------------------------------------------------------- Tim Daneliuk tundra@tundraware.com PGP Key: http://www.tundraware.com/PGP/