Networking Forums

Networking Forums > Computer Networking > Linux Networking > Shorewall and ping latency

Reply
Thread Tools Display Modes

Shorewall and ping latency

 
 
Jacob Bunk Nielsen
Guest
Posts: n/a

 
      11-08-2005, 07:43 AM
Hi

I'm setting up a firewall based on Shorewall 2.2 from Debian stable
(sarge). It seems to work just fine, but I have a weird thing
happening when using ping and other ICMP traffic.

The box is a 2.8 GHz with 1 GB of memory. It has 3 gigabit ethernet
adapters, and I'm not loading it with a lot of traffic at this point.

When shutting down Shorewall I have a ping latency at around 0.1 ms
from my local network to the firewall, but as soon as I enable
Shorewall the latency goes up to about 25-30 ms.

However, if I traceroute through the firewall to some other host on
the internet it replies quickly in less than 0.2 ms. To illustrate:

$ ping -c 10 -q 10.0.0.8
PING 10.0.0.8 (10.0.0.8): 56 data bytes

--- 10.0.0.8 ping statistics ---
10 packets transmitted, 10 packets received, 0% packet loss
round-trip min/avg/max = 26.5/34.7/100.0 ms

$ traceroute -I www.webpartner.dk
traceroute to www.webpartner.dk (195.184.96.72), 30 hops max, 40 byte packets
1 10.0.0.8 (10.0.0.8) 0.221 ms 0.186 ms 0.238 ms
2 213.173.237.225 (213.173.237.225) 16.764 ms 14.519 ms 14.098 ms
3 213.173.240.90 (213.173.240.90) 20.972 ms 24.657 ms 19.967 ms
4 213.173.240.89 (213.173.240.89) 22.925 ms 34.553 ms 22.194 ms
5 195.184.96.72 (195.184.96.72) 24.843 ms 9.660 ms 10.103 ms

213.173.237.225 is my router to the internet, it's not the world's
fastest router, but still faster than what what the above traceroute
shows. If I ping it through another firewall I get:

$ ping -c 10 -q 213.173.237.225
PING 213.173.237.225 (213.173.237.225) 56(84) bytes of data.

--- 213.173.237.225 ping statistics ---
10 packets transmitted, 10 received, 0% packet loss, time 9012ms
rtt min/avg/max/mdev = 1.300/1.832/4.290/0.903 ms

I see the same pattern even if I cut the rules down to only permitting
ping. Does anyone have a clue as to what's happening? I'm using a
newly compiled 2.6.14 kernel, but saw the same behavior with an older
2.6.8-2 kernel.

--
Jacob
 
Reply With Quote
 
 
 
 
Jacob Bunk Nielsen
Guest
Posts: n/a

 
      11-15-2005, 11:13 AM
Jacob Bunk Nielsen <(E-Mail Removed)> writes:

> I'm setting up a firewall based on Shorewall 2.2 from Debian stable
> (sarge). It seems to work just fine, but I have a weird thing
> happening when using ping and other ICMP traffic.
>
> The box is a 2.8 GHz with 1 GB of memory. It has 3 gigabit ethernet
> adapters, and I'm not loading it with a lot of traffic at this point.
>
> When shutting down Shorewall I have a ping latency at around 0.1 ms
> from my local network to the firewall, but as soon as I enable
> Shorewall the latency goes up to about 25-30 ms.


I have now tried to disable Shorewall, but run the same iptables
ruleset as Shorewall creates without starting the rest of Shorewall.
This doesn't help, so it must be an iptables related problem that I
have run into.

I could still use a hint to resolve this issue.

--
Jacob
 
Reply With Quote
 
Jacob Bunk Nielsen
Guest
Posts: n/a

 
      12-16-2005, 09:19 AM
Jacob Bunk Nielsen <(E-Mail Removed)> writes:

> I'm setting up a firewall based on Shorewall 2.2 from Debian stable
> (sarge). It seems to work just fine, but I have a weird thing
> happening when using ping and other ICMP traffic.


I resolved this issue, have a look at
<http://sourceforge.net/mailarchive/message.php?msg_id=14195105> if
you care to see what the solution was.

--
Jacob
 
Reply With Quote
 
Bit Twister
Guest
Posts: n/a

 
      12-16-2005, 01:42 PM
On Tue, 08 Nov 2005 09:43:48 +0100, Jacob Bunk Nielsen wrote:
> Hi
>
> I'm setting up a firewall based on Shorewall 2.2 from Debian stable


I would think I would setup 3.0 if it were me.
http://www.shorewall.net/
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
high ping latency correlation with high server activity Tal Bar-Or Windows Networking 0 04-29-2008 08:08 AM
Shorewall Kees de Koster Linux Networking 3 06-29-2005 05:48 AM
Help : Mandrake 9.2 Shorewall, can't telnet or ssh.. can ping though! Dave Linux Networking 1 03-05-2004 08:49 AM
LinkSys BEFSR81 v1: Bad latency/ping issues of over a second. Anyone else seen it? Bloke at the pennine puddle (Replace n.a.v.d with vodafone.net.) Broadband 4 10-22-2003 06:52 PM
DNS knocking on my Shorewall Kevin Linux Networking 3 08-27-2003 05:27 PM



1 2 3 4 5 6 7 8 9 10 11