The Performance Optimization Scheme and Implementation of Netfilter/iptables Firewall

Zhu Licai,Yang Shoubao,Song Shunhong
DOI: https://doi.org/10.3321/j.issn:1002-8331.2006.15.035
2006-01-01
Abstract:As the increasing of network bandwidth and firewall ruleset,the function of netfilter/iptables needs higher performance.In this paper,we first analyze the principle of netfilter/iptables,and then bring up a scheme of grouping the firewall rules to prompt the rule match efficiency.At last we implement it in Linux.From the result of performance test,we can reach a conclusion that this measure can increase the firewall performance.
What problem does this paper attempt to address?