| ▲ | gerdesj 7 hours ago | |
>Oh, the other day I had just 70 `iptables -m set --match-set` rules, and did you know how apparently inefficient source/destination address hashing algorithm for the set match is?! It was debugged with perf as well! >I'm talking about ~4Gbit/s sudden limitation on a 10Gbit link. I think you need to look into things if 70 IPs in a table are causing issues, such that a 10Gb link ends up at four Gb/s. I presume that if you remove the ipset, that 10Gb/s is restored? Testing throughput and latency is also quite a challenge - how do you do it? | ||