Re: [ovs-discuss] High cpu usage by vswitchd on SYN scan

2013-09-23 Thread Justin Pettit
I would try using version 1.11, which allows wildcarding in the kernel. You'll need to upgrade both your userspace and kernel to get the benefit. The benefit will depend on your flow table, but most users should see a substantial increase in flow set up rate. --Justin On Sep 23, 2013, at 3:

[ovs-discuss] High cpu usage by vswitchd on SYN scan

2013-09-23 Thread Andrey Korolyov
Hello, Recently discovered that one of our clients had started portscanning using some windows utility, bringing ovs-vswitchd to begin packetdrop in openflow mode at just 300pps to unique addresses, so 300 flows/second was created. For regular legitimate TCP vswitchd may survive about 10kpps and a