Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #455 > unrolled thread

IPv6 Connection Tracking Excess CPU usage

Started byWashington Ratso <jobhunts02@aol.com>
First post2011-07-28 17:18 -0700
Last post2011-08-01 16:34 +0000
Articles 5 — 5 participants

Back to article view | Back to comp.os.linux.networking


Contents

  IPv6 Connection Tracking Excess CPU usage Washington Ratso <jobhunts02@aol.com> - 2011-07-28 17:18 -0700
    Re: IPv6 Connection Tracking Excess CPU usage Stephane Le Men <slm@nullpart.fr> - 2011-07-30 07:35 +0200
      Re: IPv6 Connection Tracking Excess CPU usage Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-07-30 07:19 +0000
        Re: IPv6 Connection Tracking Excess CPU usage Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-07-30 13:18 +0200
        Re: IPv6 Connection Tracking Excess CPU usage Rick Jones <rick.jones2@hp.com> - 2011-08-01 16:34 +0000

#455 — IPv6 Connection Tracking Excess CPU usage

FromWashington Ratso <jobhunts02@aol.com>
Date2011-07-28 17:18 -0700
SubjectIPv6 Connection Tracking Excess CPU usage
Message-ID<a4afc1e9-9f34-44f5-bc55-aa57c3bc2494@r11g2000prd.googlegroups.com>
I am running Linux 2.6.26 on my board.  When I enable IPv6 connection
tracking support, i.e., CONFIG_NF_CONNTRACK_IPV6=y, and send 3
megabits of data to the board with iperf, the CPU usage according to
top for events/0 goes up to 99-100%.  Without CONFIG_NF_CONNTRACK_IPV6
enabled, the CPU usage for events/0 is only 17-18%.

Has anyone else seen this issue?  Is there a fix?

[toc] | [next] | [standalone]


#457

FromStephane Le Men <slm@nullpart.fr>
Date2011-07-30 07:35 +0200
Message-ID<j105eu$sob$1@speranza.aioe.org>
In reply to#455
On 07/29/2011 02:18 AM, Washington Ratso wrote:
> I am running Linux 2.6.26 on my board.  When I enable IPv6 connection
> tracking support, i.e., CONFIG_NF_CONNTRACK_IPV6=y, and send 3
> megabits of data to the board with iperf, the CPU usage according to
> top for events/0 goes up to 99-100%.  Without CONFIG_NF_CONNTRACK_IPV6
> enabled, the CPU usage for events/0 is only 17-18%.

That fact exhibits the proof that the CONFIG_NF_CONNTRACK_IPV6 kernel 
code has low performance. It is not an easy job to write a good code to 
perform connection tracking.

> Has anyone else seen this issue?  Is there a fix?

Yes, but not with that flag. The fix is to update your kernel to the 
last version, and to hope kernel developers wrote a code with a better 
performance.

[toc] | [prev] | [next] | [standalone]


#458

FromJorgen Grahn <grahn+nntp@snipabacken.se>
Date2011-07-30 07:19 +0000
Message-ID<slrnj37c3u.gtj.grahn+nntp@frailea.sa.invalid>
In reply to#457
On Sat, 2011-07-30, Stephane Le Men wrote:
> On 07/29/2011 02:18 AM, Washington Ratso wrote:
>> I am running Linux 2.6.26 on my board.  When I enable IPv6 connection
>> tracking support, i.e., CONFIG_NF_CONNTRACK_IPV6=y, and send 3
>> megabits of data to the board with iperf, the CPU usage according to
>> top for events/0 goes up to 99-100%.  Without CONFIG_NF_CONNTRACK_IPV6
>> enabled, the CPU usage for events/0 is only 17-18%.

Is that by just *including* CONFIG_NF_CONNTRACK_IPV6 in your kernel,
or do you also *enable* it (using iptables, I suppose)?

> That fact exhibits the proof that the CONFIG_NF_CONNTRACK_IPV6 kernel 
> code has low performance.

Not *proof*, but an indication. I don't know iperf -- does it do
something abnormal which causes each packet to create a connection?
What are the OP's figures for IPv4?

> It is not an easy job to write a good code to 
> perform connection tracking.

No, but one would naively think the algorithm would be the same as for
IPv4.

/Jorgen

-- 
  // Jorgen Grahn <grahn@  Oo  o.   .     .
\X/     snipabacken.se>   O  o   .

[toc] | [prev] | [next] | [standalone]


#460

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2011-07-30 13:18 +0200
Message-ID<j10paa$25mr$1@saria.nerim.net>
In reply to#458
Hello,

Jorgen Grahn a écrit :
>> On 07/29/2011 02:18 AM, Washington Ratso wrote:
>>> I am running Linux 2.6.26 on my board.  When I enable IPv6 connection
>>> tracking support, i.e., CONFIG_NF_CONNTRACK_IPV6=y, and send 3
>>> megabits of data to the board with iperf, the CPU usage according to
>>> top for events/0 goes up to 99-100%.  Without CONFIG_NF_CONNTRACK_IPV6
>>> enabled, the CPU usage for events/0 is only 17-18%.
> 
> Is that by just *including* CONFIG_NF_CONNTRACK_IPV6 in your kernel,
> or do you also *enable* it (using iptables, I suppose)?

If CONFIG_NF_CONNTRACK_IPV6=y (built into the kernel, not as a module)
then IPv6 conntrack is enabled. No need to use ip6tables.

[toc] | [prev] | [next] | [standalone]


#463

FromRick Jones <rick.jones2@hp.com>
Date2011-08-01 16:34 +0000
Message-ID<j16kin$q6q$3@usenet01.boi.hp.com>
In reply to#458
Jorgen Grahn <grahn+nntp@snipabacken.se> wrote:
> On Sat, 2011-07-30, Stephane Le Men wrote:
> > On 07/29/2011 02:18 AM, Washington Ratso wrote:
> >> I am running Linux 2.6.26 on my board.  When I enable IPv6
> >> connection tracking support, i.e., CONFIG_NF_CONNTRACK_IPV6=y,
> >> and send 3 megabits of data to the board with iperf, the CPU
> >> usage according to top for events/0 goes up to 99-100%.  Without
> >> CONFIG_NF_CONNTRACK_IPV6 enabled, the CPU usage for events/0 is
> >> only 17-18%.

> Is that by just *including* CONFIG_NF_CONNTRACK_IPV6 in your kernel,
> or do you also *enable* it (using iptables, I suppose)?

> > That fact exhibits the proof that the CONFIG_NF_CONNTRACK_IPV6
> > kernel code has low performance.

> Not *proof*, but an indication. I don't know iperf -- does it do
> something abnormal which causes each packet to create a connection?

I don't track iperf all *that* closely, but suspect that it does not.
Also, I don't think it has anything like the netperf TCP_CRR
(Connect/Request/Response) or TCP_CC (Connect/Close) tests which would
be very connection establishment/tear-down heavy.

rick jones
-- 
The glass is neither half-empty nor half-full. The glass has a leak.
The real question is "Can it be patched?"
these opinions are mine, all mine; HP might not want them anyway... :)
feel free to post, OR email to rick.jones2 in hp.com but NOT BOTH...

[toc] | [prev] | [standalone]


Back to top | Article view | comp.os.linux.networking


csiph-web