Re: ipchains latency

2000-06-13 Thread Jens B. Jorgensen
10-30 seconds for telnet? Even on a 386/33 this is just way too much delay to be accounting for in packet filtering rules. I would suspect something else, like ident checking which is waiting to time out and reverse-dns lookups timing out. Often these two things are used to gather info to log

Re: ipchains latency

2000-06-13 Thread Mirek Kwasniak
On Mon, Jun 12, 2000 at 05:30:37PM -0500, Chris Brown wrote: [...] firewalling? I shouldn't think this is the problem... Are there any errors that add to connection latency that I should be looking for in the firewalling rules? It was a bug in ipchains structure in some kernels ( =2.2.10

ipchains latency

2000-06-12 Thread Chris Brown
Hello, Our company LAN is divided into two segments, and I have just finished implementing firewalling rules for the router in between them, to protect the inner network from the outside world. After meticulously designing an installing my ipchains rules, I was dismayed by the