IPfilter
[Top] [All Lists]

Re: pfil and network performance

To: "Buozis, Martynas" <martynas@ti.com>
Subject: Re: pfil and network performance
From: Vincent Fox <vbfox@ucdavis.edu>
Date: Tue, 13 Feb 2007 13:55:34 -0800
Cc: ipfilter@coombs.anu.edu.au
Delivered-to: sp-com-lists@consult.net
Delivered-to: ipfilter-list@securepoint.com
In-reply-to: <1266A6320AD3884EA8142B354DFBA31A069ECF12@dfre02.ent.ti.com>
References: <1266A6320AD3884EA8142B354DFBA31A069ECF12@dfre02.ent.ti.com>
Sender: owner-ipfilter@coombs.anu.edu.au
User-agent: Thunderbird 1.5.0.9 (X11/20061215)

I found that UDP rules with keep state caused very slow write performance on AFS. I modified my rulesets, removed all "keep state" for both pass in and out UDP rules.
We still use keep state (and keep frags) on TCP rules.

Dunno about NFS, thought this might be worth a try for you.

Buozis, Martynas wrote:
Hello

I am running IPFilter installation on Solaris 8 (Generic_117350-41).
PFIL version is  2.1.11,REV=10:54:27 11/16/06.

We noticed, that PFIL is causing big impact to network performance even
when IPFilter is stopped (just PFIL is loaded) and no rules are present.
2GB file copy from NFS server took 35 minutes with PFIL loaded, while
without PFIL only 3 minutes were required to copy same file.

Can somebody advice were problem is with PFIL ?


With best regards
Martynas




<Prev in Thread] Current Thread [Next in Thread>