Subject: Re: ipfilter performance with 'count' rules on NetBSD-1.4/i386
To: Erik Rungi <>
From: Bill Sommerfeld <>
List: current-users
Date: 09/14/1999 15:33:37
The data you've collected shows a roughly linear relationship between
number of rules and forwarding delay, which makes sense assuming that
ipf is just trying rules one at a time, in order.

It's possible to build more sophisticated data structures for filter
rule matching but given that the typical ipf filter i've seen uses
fewer than 100 rules, it's not clear that this will help the typical
use of ipf..

For your application, it may make sense for you to find a different
hammer..  (what are you trying to do, anyway?)

					- Bill