Re: [ANNOUNCE]: First release of nftables

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Meelis Roos
Date: Wednesday, March 18, 2009 - 5:00 am

> Data is represented in a generic way inside the kernel and the

This sounds like a "script" downloaded to kernel and interpreted during 
each packet match. This toubles me some - doesn't this use more memory 
accesses to achieve the same work that was done in precompiled code 
before?

Have you measured the fastpath performance of kernel matching of real-life 
rulesets, compared to iptables?

-- 
Meelis Roos (mroos@linux.ee)
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [ANNOUNCE]: First release of nftables, Meelis Roos, (Wed Mar 18, 5:00 am)
Re: [ANNOUNCE]: First release of nftables, Patrick McHardy, (Wed Mar 18, 7:39 am)
Re: [ANNOUNCE]: First release of nftables, Denys Fedoryschenko, (Wed Mar 18, 7:52 am)
Re: [ANNOUNCE]: First release of nftables, Patrick McHardy, (Wed Mar 18, 7:58 am)