[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#831014: linux-image-3.16.0-4-amd64: iptables performance issue introduced by "netfilter: x_tables: validate targets of jumps"



Dear Maintainer, Dear Jeff,

I'm having the same issue.

I have an old firewall running Wheezy, applying the firewall take less
than 30 seconds.
I installed a new server in Jessie, now it takes more than 60 seconds to apply.

To confirm the issue I did few more tests on my old servers:
- with the wheezy-backports kernel (3.16.7-ckt25-2+deb8u3~bpo70+1) I
have the same issue (applying the firewall take more than 60 seconds),
- with an old wheezy-backports kernel downloaded on
snapshot.debian.org (3.16.7-ckt25-2~bpo70+1): I have no issue (less
than 30 seconds to apply).


Jeff, did you had to build your own kernel to fix this issue?
Ideally, I would like to avoid this solution if possible.


Thanks.


Regards,
Thomas


Reply to: