From owner-freebsd-pf@FreeBSD.ORG Tue Mar 24 23:33:03 2009 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 0905D1065695 for ; Tue, 24 Mar 2009 23:33:03 +0000 (UTC) (envelope-from myself@rojer.pp.ru) Received: from wooster.rojer.pp.ru (wooster.rojer.pp.ru [80.68.242.188]) by mx1.freebsd.org (Postfix) with ESMTP id B30A68FC1F for ; Tue, 24 Mar 2009 23:33:02 +0000 (UTC) (envelope-from myself@rojer.pp.ru) Received: from wooster.rojer.pp.ru (localhost [127.0.0.1]) by wooster.rojer.pp.ru (Postfix) with ESMTP id B11FF114A0 for ; Wed, 25 Mar 2009 02:14:00 +0300 (MSK) X-Spam-Checker-Version: SpamAssassin 3.2.5-rojer (2008-06-10) on wooster.rojer.pp.ru X-Spam-Level: X-Spam-Status: No, score=-4.4 required=5.0 tests=ALL_TRUSTED,BAYES_00 autolearn=ham version=3.2.5-rojer Received: from [127.0.0.1] (localhost [127.0.0.1]) by wooster.rojer.pp.ru (Postfix) with ESMTPA id 887FE11468 for ; Wed, 25 Mar 2009 02:13:56 +0300 (MSK) Message-ID: <49C96933.4030901@rojer.pp.ru> Date: Tue, 24 Mar 2009 23:13:55 +0000 From: Deomid Ryabkov User-Agent: Thunderbird 2.0.0.21 (X11/20090318) MIME-Version: 1.0 To: freebsd-pf@freebsd.org Content-Type: text/plain; charset=KOI8-R; format=flowed Content-Transfer-Encoding: 7bit Subject: 8.0-CURRENT: having pf enabled without any rules impacts forwarding performance X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 24 Mar 2009 23:33:03 -0000 i have a machine with nc running through it. with pf disabled, i see 960-970 mbit/s through it (as reported by systat -ifstat). just having pf enabled, with empty ruleset: # pfctl -vs nat # pfctl -vs rules # reduces throughput to about 700 mbit. this seems wrong. any ideas why this might be happening? OS: 8.0-CURRENT #0: Fri Feb 27 04:20:49 MSK 2009 thanks. -- Deomid Ryabkov aka Rojer myself@rojer.pp.ru rojer@sysadmins.ru ICQ: 8025844