Firewall Wizards mailing list archives

Re: Firewall performance


From: Darren Reed <darrenr () reed wattle id au>
Date: Tue, 29 Jun 1999 16:42:47 +1000 (EST)

In some email I received from David C Niemi, sie wrote:


By the way, 3 copies for routing an IP packet under Linux is way off, not
even Linux 1.0 did that many ;^)  2.2 will typically do a DMA in and a DMA
out and appropriate futzing of headers; and there is a special case to do
direct NIC-to-NIC transfers with certain hardware to cut out one of those
DMAs (if I understand NET_FASTROUTE option correctly).

So how do you firewall packets which go from one NIC to the other, directly ?

Such features whilst nice for some applications are perhaps best left alone
when it comes to firewalling lest something sneak through unbeknowst to you.

Darrennn



Current thread: