jamal wrote:
OK I would need that to recreate what I do now with IMQ hooked after deNAT so I can see local addresses and use connbytes in prerouting mangle (though that's on my 2.4 I can't get connbytes to work with latest netfilter yet anyway)
Things are OK for me with IMQ - low bandwidth and not many filters seem fine. At high bandwidth/lots of filters it seems problematic - but then most people can use dummy now :-) I'll have to re-run a test I did recently which was lots of tc filter matches at 8000pps - on egress IMQ was almost as good as directly on eth0. On ingress it was more than 10X worse. I also wish someone else would start writting some of these actions ;-> Wanna right the tracking one? I could help - wink.
I really should try and get into coding more though, apart from a few small hacks I have had no practice with C/kernel stuff. Andy. |
| Previous by Date: | Re: iptables breakage WAS(Re: dummy as IMQ replacement, Patrick McHardy |
|---|---|
| Next by Date: | Re: iptables breakage WAS(Re: dummy as IMQ replacement, Patrick McHardy |
| Previous by Thread: | Re: iptables breakage WAS(Re: dummy as IMQ replacement, jamal |
| Next by Thread: | IMQ again WAS(Re: iptables breakage WAS(Re: dummy as IMQ replacement, jamal |
| Indexes: | [Date] [Thread] [Top] [All Lists] |