syncookie CPU load

Hien Phan phanquochien at gmail.com
Sat Aug 29 07:12:06 UTC 2015


Hello,

pf has built-in synproxy support, you could try it.

On Sat, Aug 29, 2015 at 1:09 PM, Dmitry Mikhailov <dmitry at pushware.net>
wrote:

> Doing a SYN flood test with FreeBSD on Xeon D (8 core) with syncookies
> enabled and the CPU load is around 20% (interrupts) at 150K pps. Is there
> any way reconfigure FreeBSD to bring this load down? Linux has a solution
> with netfilter synproxy which would not notice this low pps rate so I am
> wondering whether something similar is possible with FreeBSD?
>
> Dmitry
> _______________________________________________
> freebsd-questions at freebsd.org mailing list
> https://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to "
> freebsd-questions-unsubscribe at freebsd.org"
>


More information about the freebsd-questions mailing list