Re: how many IPFW rules?



I'm not going to brag but this is one hell of a server :-) hardware prices were not a concern when we built it.

Thanks for the pointer I'll definitely manpage it now that I know where to start looking.

------Original Message------
From: Dan Nelson
Sender:
To: eBoundHost: Artur
Cc: freebsd-questions@xxxxxxxxxxx
Sent: Oct 30, 2007 23:36
Subject: Re: how many IPFW rules?

In the last episode (Oct 30), eBoundHost: Artur said:
Hello FreeBSD people!

I have a smtp server under attack by what seems like a large botnet. My
inetd is choking under the load and not allowing real mail through. I've
successfully used tshark to find the offenders and put them into ipfw
firewall for port 25.

So here is my question, I'm currently blocking 55,529 ip addresses and the
server seems pretty snappy, with no noticible load or lag. How many more
rulesets will I be able to handle before things start getting fuzzy?

If you've created 55K separate rules and you're not seeing any
slowdown, then you must have a fast machine :) Using an ipfw table
should be even better, though. That lets you load any number of
ip/netmask pairs into a tree-based lookup table and match all addresses
using one ipfw rule. The ipfw manpage has examples.

--
Dan Nelson
dnelson@xxxxxxxxxxxxxxx



Best Regards,

Artur
eBoundHost
http://www.eboundhost.com
artur@xxxxxxxxxxxxxx_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"

Relevant Pages

  • Re: how many IPFW rules?
    ... I have a smtp server under attack by what seems like a large botnet. ... inetd is choking under the load and not allowing real mail through. ... successfully used tshark to find the offenders and put them into ipfw ... If you've created 55K separate rules and you're not seeing any ...
    (freebsd-questions)
  • Re: True Memory Use
    ... We had to actually measure our server (it can handle 1300 ... You have to measure it under load. ... Note that you have to expect 70 seconds for a reverse DNS lookup; ... But of course the GUI *does* consume cycles, so only load simulation is ...
    (microsoft.public.vc.mfc)
  • Re: the future of applications in JavaScript?
    ... more than one server has to be up for success. ... I can't imagine that a brower rendering engine needs to be hand written ... One is make the browser smarter and have longer load times ...
    (comp.lang.javascript)
  • Re: Can not change screen resolution (Fedora 5, gnome)
    ... It seems like I am not able to change my x server ... screen resolution from ... Load "extmod" ... Section "Monitor" ...
    (Fedora)
  • Re: Starting X - was Re: Vista / FreeBSD dual boot
    ... X connection to:0.0 broken (explicit kill or server shutdown) ... xorg-fonts-100dpi-7.3 X.Org 100dpi bitmap fonts ... Identifier "X.org Configured" ... Load "extmod" ...
    (freebsd-questions)