Re: Update: Alternate port randomization approaches

2004-12-30 Thread Mike Silbersack
On Wed, 29 Dec 2004, Maxim Konovalov wrote: On Wed, 29 Dec 2004, 03:02-0600, Mike Silbersack wrote: This appears to work for Igor, and it seems safe enough to commit before 4.11-RC2. But, if possible, I'd like a few more sets of eyes to doublecheck the concept and code; please take a look at it if

Re: Update: Alternate port randomization approaches

2004-12-29 Thread Maxim Konovalov
On Wed, 29 Dec 2004, 03:02-0600, Mike Silbersack wrote: > On Sat, 18 Dec 2004, Mike Silbersack wrote: > > > There have been a few reports by users of front end web proxies and other > > systems under FreeBSD that port randomization causes them problems under > > load. This seems to be due to a co

Update: Alternate port randomization approaches

2004-12-29 Thread Mike Silbersack
On Sat, 18 Dec 2004, Mike Silbersack wrote: There have been a few reports by users of front end web proxies and other systems under FreeBSD that port randomization causes them problems under load. This seems to be due to a combination of port randomization and rapid connections to the same hos

Re: Alternate port randomization approaches

2004-12-19 Thread Maxim Konovalov
Hi Mike, On Sat, 18 Dec 2004, 04:03-0600, Mike Silbersack wrote: [...] > Although this isn't a perfect fix, I think that it should be > acceptable for the vast majority of systems, and I'd like to get it > in before 4.11-release ships. To be conservative, I'll probably > choose a value like 5, w

Alternate port randomization approaches

2004-12-18 Thread Mike Silbersack
There have been a few reports by users of front end web proxies and other systems under FreeBSD that port randomization causes them problems under load. This seems to be due to a combination of port randomization and rapid connections to the same host causing ports to be recycled before the IS