Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 28 Nov 2004 19:26:17 -0500
From:      Chuck Swiger <cswiger@mac.com>
To:        Andrew Seguin <asegu@borgtech.ca>
Cc:        freebsd-net@freebsd.org
Subject:   Re: FreeBSD 5.3 Networking performance problem
Message-ID:  <41AA6CA9.6020008@mac.com>
In-Reply-To: <007f01c4d3b2$12597af0$cad435a1@mojlaptop>
References:  <007f01c4d3b2$12597af0$cad435a1@mojlaptop>

next in thread | previous in thread | raw e-mail | index | archive | help
Andrew Seguin wrote:
> We have about 100 computers active, generating a stream of approximately
> 80-90K packets per minute for a load I estimate* to be a little under
> 10Mbps. Overall the firewall will need to filter for a /24 subnet.

OK.

> *Configuration:
>   Hardware:
> The firewall is a Celeron 900Mhz with 128MB ram (more on the way) with one
> rl and one sis based network cards.

My first suggestion would be to bin the rl NIC and replace it with an fxp or 
dc-based NIC.  Realtek NICs are infamous for working poorly or not working 
reliably at all under load.

[ ... ]
> I then tested with the whole school going through the firewall: very bad.
> packets were being droped and ping times were around 600ms. Internet was
> pretty much unuseable.

This report sounds consistent, although you could also have a bad cable or 
switch port, too.  It would be useful to you to look into the output of 
"netstat -i" and "netstat -s", and any statistics which might be available on 
your switches (if they have management & per-port stats).

-- 
-Chuck



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?41AA6CA9.6020008>