Re: ipfw rules vs routes to localhost?

_at_babolo.ru
Date: 05/30/03

  • Next message: akanwar_at_digitarchy.com: "RE: gratuitous ARP with em interface."
    To: Paul Chvostek <paul@it.ca>
    Date: Fri, 30 May 2003 02:19:47 +0400 (MSD)
    
    

    > I'm considering:
    >
    > ipfw add N deny ip from a.b.c.d to any
    >
    > vs.
    >
    > route add -host a.b.c.d localhost
    >
    > I need to block traffic to a number of IP addresses. I thought I'd use
    > ipfw to avoid things like UDP DNS lookups that might come in ant take up
    > resources while my system tried to respond, but it's been suggested on
    > another list that setting routes to localhost will use less resources.
    > Ideally, I'd like to be able to block a few tens of thousands of IPs.
    >
    > What's the scoop?
    ipfw with huge list works slow.
    Dont try huge route tables.

    use in kernel:
    pseudo-device disc #Discard device (ds0, ds1, etc)

    and
    ifconfig ds0 inet 0.0.0.1/32 (or else)
    route add -host a.b.c.d 0.0.0.1
    instead of localhost

    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"


  • Next message: akanwar_at_digitarchy.com: "RE: gratuitous ARP with em interface."

    Relevant Pages

    • Re: tricking myself w/ multihoming
      ... > The default route is also on rl1: ... > This setup lets outgoing SMTP transactions go out my public block. ... route to 198.175.254.1 rather than playing ipfw games. ...
      (freebsd-net)
    • Re: ipfw rules vs routes to localhost?
      ... > ipfw with huge list works slow. ... route to the loopback interface does not offer you this luxury. ... Do you Yahoo!? ... Calendar - Free online calendar with sync to Outlook. ...
      (freebsd-net)
    • Re: 2 adsl connections load balancing with natd/ipfw
      ... ipfw add prob 0.5 allow ip from any to any out via em1 fwd 192.168.2.1 ... a route to 192.168.2.1 via default route) ... and Client A and Client B are also FreeBSD ... >>>> paths from the ISP to you. ...
      (freebsd-isp)
    • ipfw rules vs routes to localhost?
      ... route add -host a.b.c.d localhost ... ipfw to avoid things like UDP DNS lookups that might come in ant take up ... another list that setting routes to localhost will use less resources. ...
      (freebsd-net)
    • Re: ipfw rules vs routes to localhost?
      ... > ipfw to avoid things like UDP DNS lookups that might come in ant take up ... > another list that setting routes to localhost will use less resources. ... ip_input, which is good, but _all_ packets have to go through ...
      (freebsd-net)

  • Quantcast