OpenVZ Forum


Home » General » Support » Can you use "ipset" with OpenVZ 7 / Virtuozzo 7? (...if so, how can you enable it for CT's?)
Re: Can you use "ipset" with OpenVZ 7 / Virtuozzo 7? [message #53550 is a reply to message #53549] Mon, 17 June 2019 11:18 Go to previous message
wsap is currently offline  wsap
Messages: 60
Registered: March 2018
Location: Halifax, NS
Member
Hey HHawk,

I haven't specifically used Juggernaught before, but I have used a few other firewall solutions and, as long as NETFILTER=full is enabled on the container, they've all worked great.

Even with vz7 I *have* seen slowdowns when too many containers have too many standard iptables rules per node, however I haven't analyzed it in any great detail. This is the big advantage of ipset; you can use that to set up huge chains of rules without any such slowdowns. Hopefully juggernaught uses it too?

I generally try to keep my numiptent to under 5000 per container. I *think* when I ran into trouble it was around 20000 rules across all containers on a node. I'd suggest that juggernaught start using ipset instead. If that's not likely to happen, could always check out csf -- it uses ipset.
 
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Previous Topic: OpenVZ 7 + mdadm slow rebuild
Next Topic: OpenVZ7 - Failed to yum update
Goto Forum:
  


Current Time: Tue Mar 19 04:36:53 GMT 2024

Total time taken to generate the page: 0.02313 seconds