LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

RE: LVS and "firewall sandwich"

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: RE: LVS and "firewall sandwich"
From: "Peter Mueller" <pmueller@xxxxxxxxxxxx>
Date: Thu, 30 Dec 2004 11:26:47 -0800
> Has anyone on this list use LVS to load balance firewalls?

Yes, see the list archives.

> If so, what kind of limitations did you see with regard to 
> Mbps and kpps?

The limit is in the PCI bus.  If you are pushing the limit of the LVS PCI bus
then it won't help to use LVS.

Anyway, I have not gotten more than 100kpps unless using NAPI.  Some people
report getting up to 1.2mpps (!) a few years ago with intel gigabits, 64-bit
66mhz individual cards & buses.  These figures are with 64 byte packets.
There was a post on quagga archive recently about this, check there for more
details.

> Did you run into any issues with stateful connections and how many
> simultaneous connections did it handle?

I'm sure if you run iptables on a router it will drop your numbers, probably
by a lot.

Regards,

P

<Prev in Thread] Current Thread [Next in Thread>