On Fri, 21 Feb 1997, m* wrote:
> how much kernel overhead is generated by compiled-in firewall
> functionality, i.e. ipfwadm?
Unless you're ipfw'ing a T3, then probably not much of a concern.
> is the impact on system performance negligible or of concern?
Usually negligible. Check and see if a lot of kernel time is being eaten
up. If so, turn off the filters for a few seconds and then see if the
time drops. If so, then yes it is. If you're cpu is idle then no, it's
not.
I've got a P100 filtering at approx. T1 levels of traffic. I can't even
detect the impact of filtering.
__
Todd Graham Lewis Mindspring Enterprises tlewis @
mindspring .
com
References:
|
|