Thanks for the hints. I've replied the questions below. I was still wondering what could be considered "maximum" session concurrency that I could expect, with various hardware combinations? Is anyone that can tell me if it could be feasible with OpenBSD and better hardware? Even if we have to move to a different platform than i386, like maybe a Sun Fire T1000, as I don't see that as being a problem if it solves our issues. What we would like most if possible is to find something that could scale in the million concurrent sessions, but with a couple of thousands of new sessions per second. I know it's something very hardware demanding and even most enterprise class firewalls like Juniper and Fortinet don't scale much more than a million even on their higher end models, so that's why I'm curious as to what I could expect a PF setup to scale. Thanks again, Steve Johnson Stuart Henderson wrote:Mostly on the outside, but it was a "nice to have". I'll test to see if it helps a lot by just scrubbing in on the outside interface. Yes, I am at the moment. However, it's the default gateway interface and so I can't really skip filtering on that interface. I'll try skipping on the inside interface, since the traffic will have already been validated and see if that changes much. I'm also trying to just skip session based filtering on that service as well, since it's one of the first pass quick rule and see if it helps. I was still seeing a bit of congestion though. Good to know, thought most people didn't want to have too much stuff pasted in the emails.
| Greg Kroah-Hartman | [PATCH 005/196] Chinese: add translation of SubmittingDrivers |
| Andrew Morton | Re: 2.6.23-rc4-mm1 |
| Rafael J. Wysocki | Re: Slow DOWN, please!!! |
| Artem Bityutskiy | Re: [RFC PATCH 05/26] UBIFS: add file-system build |
git: | |
| Benjamin Collins | Re: git-gui hangs on read |
| Jon Smirl | ! [rejected] master -> master (non-fast forward) |
| Jakub Narebski | Re: Corruption: empty refs/heads in otherwise filled repo: cannot clone? |
| Johannes Schindelin | Re: [ANNOUNCE] GIT 1.5.4 |
| Mattieu Baptiste | Re: Real men don't attack straw men |
| Todd Pytel | IDE or SCSI virtual disks for VMWare image? |
| Douglas Maus | NFS mount by non-root |
| Joel Wiramu Pauling | Re: Suggested PF Setup when using BitTorrent? |
| Stephen Tweedie | [ANSWER] Re: NR_INODE / NR_FILE |
| Bill Bogstad | Re: A question about ramdisks |
| Jim Winstead Jr. | FAQ - Where is it? |
| Steve M. Robbins | another adduser utility available |
| types of kernel | 36 minutes ago | Linux kernel |
| magical mounts | 17 hours ago | Linux kernel |
| Problem in scim in Fedora 9 | 18 hours ago | Linux general |
| The new Western Digital power saving drives | 18 hours ago | Hardware |
| Battery Maximizer Software | 1 day ago | Linux kernel |
| windows folder creation surprise | 1 day ago | Windows |
| Firewall | 2 days ago | OpenBSD |
| IP layer send packet | 2 days ago | Linux kernel |
| dtrace for linux available | 3 days ago | Linux kernel |
| Unable to mount ramdisk image using UBoot while upgrading to 2.6.15 kernel for a MPC8540 based target | 3 days ago | Linux kernel |
