I found that UDP rules with keep state caused very slow write performance on AFS. I modified my rulesets, removed all "keep state" for both pass in and out UDP rules.
We still use keep state (and keep frags) on TCP rules.

Dunno about NFS, thought this might be worth a try for you.

Buozis, Martynas wrote:
Hello

I am running IPFilter installation on Solaris 8 (Generic_117350-41).
PFIL version is  2.1.11,REV=10:54:27 11/16/06.

We noticed, that PFIL is causing big impact to network performance even
when IPFilter is stopped (just PFIL is loaded) and no rules are present.
2GB file copy from NFS server took 35 minutes with PFIL loaded, while
without PFIL only 3 minutes were required to copy same file.

Can somebody advice were problem is with PFIL ?


With best regards
Martynas



Reply via email to