Unix Technical Forum

Re: PF State Expiration Model for Huge Amount of States

This is a discussion on Re: PF State Expiration Model for Huge Amount of States within the lucky.openbsd.tech forums, part of the OpenBSD category; --> * Teemu Takanen <Teemu.Takanen@tecnomen.com> [2006-05-19 11:55]: > On Fri, 19 May 2006, joerg@britannica.bec.de wrote: > >>PF state entries should ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > lucky.openbsd.tech

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-22-2008, 12:28 PM
Henning Brauer
 
Posts: n/a
Default Re: PF State Expiration Model for Huge Amount of States

* Teemu Takanen <Teemu.Takanen@tecnomen.com> [2006-05-19 11:55]:
> On Fri, 19 May 2006, joerg@britannica.bec.de wrote:
> >>PF state entries should be modified to include one more RB-tree entry,
> >>used for state expiration.

> >The problem with this approach is that any longer living connection has
> >far more updates than actual expiring states. It should also be kept in
> >mind that this adds a lot of cache trashing due to the constant tree
> >updates.

> This is a valid concern. However at least I find it practically impossible
> to get PF firewall machine under any practical CPU/memory load before
> packet loss starts to happen because of state expiration sweeps.


I have had pf firewalls at this point more than once.
we must be careful to not waste CPU power, you need as much headroom as
possible for DoS style attacks.

> So yes, this might be expensive, but it still improves practical
> performance in my opinnion.


not acceptable. we'll need a better solution.
and yes, it is not easy to solve at all. we talked about that before.

--
BS Web Services, http://www.bsws.de/
OpenBSD-based Webhosting, Mail Services, Managed Servers, ...
Unix is very simple, but it takes a genius to understand the simplicity.
(Dennis Ritchie)

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 03:39 PM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com