I've been running ipfilter v3.4 on OpenBSD 2.9 as a bridging firewall for 2
years now and haven't had problems until recently when it seems that I'm
having some performance problems.

First some stats:
*This setup is running on a PIII-500MHz, 256MB RAM, with 2 NICs (fxp's).
*There are 13 servers behind the firewall.
*The firewall is passing about 250 KB/s out and about 30 KB/s in, with
spikes up to 500 KB/s out and 90 KB/s in.
*I'm averaging about 3000 states at any one time with about 500 new states
created per minute.
*I'm also passing about 600 packets per second.
*I have 166 rules and I don't use "head"/"group"

I'm having problems where mid-day I'm staring to get icmp packet loss (up to
50% for couple of minutes) at the firewall (running mtr to one of the
machines behind the firewall).  My network provider has tested the
connection and says that it's not coming from their side.  Is anyone running
ipfilter on a similarly loaded firewall?  Should I start optimizing the
rules with head/group?  Maybe I should consider upgrading ipfilter to a
newer version?

Any comments/suggestions will be greatly appreciated.  Thanks,

Marcin

Reply via email to