RE: Firewall & DSL performance

From: Darryl Hoar (darryl_at_osborne-ind.com)
Date: 03/10/04

  • Next message: Remko Lodder: "RE: Strange cvsup problem"
    To: "'Mike Jackson'" <mj@sci.fi>
    Date: Wed, 10 Mar 2004 08:10:05 -0600
    
    

    Well,
    last night I changed the ipf.rules file to be:

    pass in all keep state
    pass out all keep state

    to completely open my firewall to test my performance.

    Well, it didn't make a lick of difference. Still got
    700K.

    If I open the firewall like I did, shouldn't performance
    be a non issue ?

    thanks,
    Darryl

    > -----Original Message-----
    > From: Mike Jackson [mailto:mj@sci.fi]
    > Sent: Tuesday, March 09, 2004 11:55 AM
    > To: Darryl Hoar
    > Subject: Re: Firewall & DSL performance
    >
    >
    > Darryl Hoar (darryl@osborne-ind.com) wrote:
    > >
    > > Problem:
    > > Recently, our ISP upgraded (at no charge) our connection
    > from 512K to
    > > 1.5Mb. When testing from a computer on my Lan, I was only
    > seeing about
    > > 700K. Testing at the box on the side of my house yielded
    > 1.5Mb. Testing
    > > at the jack inside also yielded 1.5Mb. So, my firewall seems to be
    > > slowing things down.
    >
    > Run `top' and watch the memory and processor usage when
    > downloading an iso
    > from some internet site.
    >
    > Open another terminal and run `iostat -odICTw 2 -c 9', to
    > watch your io
    > performance.
    >
    > Open another terminal and run `vmstat -w 5', to watch virtual memory
    > statistics.
    >
    > Finally, a slow processor just might be the bottleneck. For
    > example, if
    > you put a gigabit ethernet card in a P4 and one in a P2, you will most
    > likely not get full speed - especially if there is kernel level packet
    > interception going, e.g. ipsec, nat, or firewall filters.
    >
    > HTH,
    > --
    > Mike Jackson
    >
    _______________________________________________
    freebsd-questions@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"


  • Next message: Remko Lodder: "RE: Strange cvsup problem"

    Relevant Pages

    • Re: cant view movies
      ... Temporarily shut down your firewall and try to watch a clip. ... > movie clip, I only see a green screen but i can still hear sound. ... > me what I'm missing from my computer because i used the restore disk the ...
      (microsoft.public.windowsxp.video)
    • RE: Change Port 444 to 443, 3. Try
      ... I mean not my own firewall. ... My default Web Site watch on 443 and WSS watch on 444. ... After that both watch on port 443. ...
      (microsoft.public.sharepoint.windowsservices)
    • i cant play streaming audio or video. error 0xC00D1198 cant connect to server
      ... I have MLB.TV installed to watch baseball games thinking ... It created a firewall and I couldn't watch the games ... any streaming audio or video from the web. ...
      (microsoft.public.windowsmedia.player)
    • Re: Computer??
      ... I have no security issues with either one. ... But you are behind a firewall. ... watch our office staff try to cope with a steady stream ...
      (rec.photo.digital)
    • Re: monitoring IP traffic
      ... > that leads to the outside world, and watch what the firewall does ...
      (Fedora)