Received: with ECARTIS (v1.0.0; list netdev); Wed, 19 Jan 2005 07:04:02 -0800 (PST) Received: from ctg-msnexc01.staff.berbee.com (msn-office-flr2.binc.net [64.73.12.254]) by oss.sgi.com (8.13.0/8.13.0) with ESMTP id j0JF3sZx012894 for ; Wed, 19 Jan 2005 07:03:55 -0800 Received: from localhost ([172.30.254.220] RDNS failed) by ctg-msnexc01.staff.berbee.com with Microsoft SMTPSVC(6.0.3790.0); Wed, 19 Jan 2005 09:03:46 -0600 From: "Jeremy M. Guthrie" Reply-To: jeremy.guthrie@berbee.com Organization: Berbee Information Networks To: netdev@oss.sgi.com Subject: Re: V2.4 policy router operates faster/better than V2.6 Date: Wed, 19 Jan 2005 09:03:42 -0600 User-Agent: KMail/1.7.2 Cc: Robert Olsson References: <200501141326.29575.jeremy.guthrie@berbee.com> <16874.24305.461492.48668@robur.slu.se> In-Reply-To: <16874.24305.461492.48668@robur.slu.se> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="nextPart1140883.XAXnEGKz2f"; protocol="application/pgp-signature"; micalg=pgp-sha1 Content-Transfer-Encoding: 7bit Message-Id: <200501190903.45671.jeremy.guthrie@berbee.com> X-OriginalArrivalTime: 19 Jan 2005 15:03:46.0304 (UTC) FILETIME=[12F75800:01C4FE38] X-Virus-Scanned: ClamAV 0.80/650/Sun Jan 2 19:00:02 2005 clamav-milter version 0.80j on 127.0.0.1 X-Virus-Status: Clean X-archive-position: 494 X-ecartis-version: Ecartis v1.0.0 Sender: netdev-bounce@oss.sgi.com Errors-to: netdev-bounce@oss.sgi.com X-original-sender: jeremy.guthrie@berbee.com Precedence: bulk X-list: netdev --nextPart1140883.XAXnEGKz2f Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline On Sunday 16 January 2005 06:32 am, Robert Olsson wrote: > Some time ago an "in-flow" GC (as opposed to timer based) was added to > the routing code look for cand in route.c. In setup like yours (and ours) > it would be better to relay on this process to a higher extent. Anyway > in /proc/sys/net/ipv4/route/ you have the files. > > gc_elasticity, gc_interval, gc_thresh etc I would avoid gc_min_interval. > > And you can play with your running system and for drops without causing > your users to much pain. I have done a little tweaking. I now hold at around 520K routes in the has= h. =20 I still drop packets every secret_interval but I've upped that counter so I= =20 don't whack all of my hash entries all that often. =2D-=20 =2D------------------------------------------------- Jeremy M. Guthrie jeremy.guthrie@berbee.com Senior Network Engineer Phone: 608-298-1061 Berbee Fax: 608-288-3007 5520 Research Park Drive NOC: 608-298-1102 Madison, WI 53711 --nextPart1140883.XAXnEGKz2f Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQBB7nbRqtjaBHGZBeURAlELAKCXBqq6fxLX9IOJiMYzGuTiaeGP6QCffX6C 5h7IY4v/kvc4yavt1ej7grk= =Mgdd -----END PGP SIGNATURE----- --nextPart1140883.XAXnEGKz2f--