Forum Discussion
Nik
Cirrus
Jun 14, 2010access restriction - pf vs irule?
we'll be making the transition from a pair of 6800s to a new viprion chassis in a few weeks. the current pair pushes about 900mb/s externally with 5k new connections per second.
about a year ago wit...
Hamish
Cirrocumulus
Jun 16, 2010That's an interesting question... I haven't had to do packet filters for a long time on F5's (Since 9.1 IIRC).
However I'm surprised that you found pf's slower and using more cpu consumption than iRules... However,w e probably need someone like Spark or another developer to give us a clear answer on who gets the packets first and what part of the switch/tmm/hostkernel/service kernel gets packets first and where the flowpath goes if you use pf's vs iRules. (I really would have expected iRules to consume more CPU though, especially if you're doing DG lookups).
Although perhaps it's something strange like the pf has to run as the management host, so packets need to be transported over to it for filtering (Just like tcpdump), vs the optimised paths that would be in place for TMM and iRule processing of packets...
H
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects