Re: [pve-devel] [PATCH pve-firewall 0/2] Fix #2450: synflood protection

2019-11-18 Thread Wolfgang Bumiller
applied, thanks On Tue, Nov 12, 2019 at 01:59:02PM +0100, Alexandre Derumier wrote: > Currently, a virtio-net + vhost-net can handle between 200-300 kpps for each > vm (with 1core/queue=1). > That mean than a vm can easily overloaded with a simple synflood (hping3 > --flood -p 80 -S targetip). >

[pve-devel] [PATCH pve-firewall 0/2] Fix #2450: synflood protection

2019-11-12 Thread Alexandre Derumier
Currently, a virtio-net + vhost-net can handle between 200-300 kpps for each vm (with 1core/queue=1). That mean than a vm can easily overloaded with a simple synflood (hping3 --flood -p 80 -S targetip). Also the conntrack of the host can be saturated easily. This patch introduce a new option, en