Dear FreeBSD Gurus!
This question are about measuring the effectiveness of the ruleset of firewall;
How to see the numbers of CPU cycles, which spends on particular FW rule ?
And better to see in conjunction: bytes(packets) / mediana of CPU cycles per packet which are accepted or rejected by this rule, - to determine which rules are highly loaded by traffic and how many CPU cycles this particular rule (mean it’s upcode) are eating.
(I read somewhere the ipfw able to doing that…)
This may be very helpful to optimizing the ruleset of whole FW.
Have a nice sunny days!
This question are about measuring the effectiveness of the ruleset of firewall;
How to see the numbers of CPU cycles, which spends on particular FW rule ?
And better to see in conjunction: bytes(packets) / mediana of CPU cycles per packet which are accepted or rejected by this rule, - to determine which rules are highly loaded by traffic and how many CPU cycles this particular rule (mean it’s upcode) are eating.
(I read somewhere the ipfw able to doing that…)
This may be very helpful to optimizing the ruleset of whole FW.
Have a nice sunny days!