Re: ipfw rules consuming CPU

2012-06-09 Thread Sami Halabi
Hi, all rules togther less than 80 rules how tablearg helps this? each ip pipe (up down) are unique... any other advices? Sami On Sat, Jun 9, 2012 at 1:15 PM, Alexander V. Chernikov melif...@freebsd.org wrote: On 09.06.2012 01:56, Sami Halabi wrote: Hi, I Manage a FreeBSD server

Re: ipfw rules consuming CPU

2012-06-09 Thread Alexander V. Chernikov
On 09.06.2012 15:19, Sami Halabi wrote: Hi, all rules togther less than 80 rules However, it is too much. You should reduce this to 10 rules or less (at least for main traffic flow). (Btw, there is related http://wiki.freebsd.org/NetworkPerformanceTuning wiki page) how tablearg

Re: ipfw rules consuming CPU

2012-06-09 Thread Michael Spratt
I have Linux FreeBSD systems running ipfw with 80 rules with 70Mb/s symmetric, passing traffic for about 1000-1200 hosts. Alexander V. Chernikov wrote: On 09.06.2012 01:56, Sami Halabi wrote: Hi, I Manage a FreeBSD server as an edge router firewall. the setup has 10G interfaces

Re: ipfw rules consuming CPU

2012-06-09 Thread Sami Halabi
on my box with 130 rules 100Mbit the cpu don't go above 5%. I daily manage 1.5-6GB. Thanks in advance, Sami On Sat, Jun 9, 2012 at 11:21 PM, Michael Spratt m...@magicislandtechnologies.com wrote: I have Linux FreeBSD systems running ipfw with 80 rules with 70Mb/s symmetric, passing traffic

ipfw rules consuming CPU

2012-06-08 Thread Sami Halabi
Hi, I Manage a FreeBSD server as an edge router firewall. the setup has 10G interfaces (ixgbe-82599EB) and 1G interfaces(em-82571EB bce-BCM5709) connected to 10G/1G switches. With the following setup i get higher cpu usage: bce1-upstream provider with little bandwidth, so i use pipes to limit