[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: loading huge number of rules in iptables (blocklist)



H.S. wrote:
...
Yes. The experiment shows that this is not going well. I was wondering if there are any alternatives. I currently have around 80,000 rules now inserted, and the process is still continuing more than 17 hours later! However, my internet connection seems to be holding up without any noticeable performance cut so far.
have you tried to make up and input for iptables-restore and blast all rules into iptables at once?
from the docs i've read this should be a faster.

on the other hand there is also nf-hipac (http://www.hipac.org/).
while i've not tried it, they claim to handle large rule sets better.

yours
albert



Reply to: