Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 02 Jul 2003 10:31:10 -0700
From:      Michael Sierchio <kudzu@tenebras.com>
To:        freebsd-ipfw@FreeBSD.ORG, freebsd-net@FreeBSD.ORG
Subject:   Performance improvement for NAT in IPFIREWALL
Message-ID:  <3F0316DE.3040301@tenebras.com>

next in thread | raw e-mail | index | archive | help

Currently, performance w/divert sockets and natd in ipfirewall
on a compute-bound platform (ELAN-133MHz) shows ipfw+natd throughput
to be 50% of that offered by ipfilter+ipnat.

Is there anything that can be done to speed up either the
performance of divert and natd?  Alternatively, could network
address translation be merged into ipfirewall?

As we move from 1000BASE-TX to 10000BASE-TX, this will become
more of an issue, even on 3GHz machines.

Comments? Suggestions? Vision?



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3F0316DE.3040301>