8.0-CURRENT: having pf enabled without any rules impacts forwarding performance

Deomid Ryabkov myself at rojer.pp.ru
Tue Mar 24 16:33:03 PDT 2009


i have a machine with nc running through it.
with pf disabled, i see 960-970 mbit/s through it (as reported by systat 
-ifstat).
just having pf enabled, with empty ruleset:

# pfctl -vs nat
# pfctl -vs rules
#

reduces throughput to about 700 mbit.
this seems wrong. any ideas why this might be happening?

OS: 8.0-CURRENT #0: Fri Feb 27 04:20:49 MSK 2009

thanks.

-- 
Deomid Ryabkov aka Rojer
myself at rojer.pp.ru
rojer at sysadmins.ru
ICQ: 8025844



More information about the freebsd-pf mailing list