摘要
通过对影响Linux包过滤防火墙性能3个关键因素的分析,采用规则组织、使用State模块以及用户自定义规则链三者相结合对Linux防火墙进行优化,目的在于让数据包做尽可能少的测试,降低包过滤防火墙响应延时。通过实验对比得出经过优化后的防火墙在一定程度上能有效降低包过滤响应延时。
Analyzes the three critical factors that affects the Linux package to filter the firewall. It adopts the method of combining the rule organization, the State module and the user-defined rule chain to optimize the Linux firewall and aims at reducing packet testing and illtering firewall response delay. Through the experiments the conclusion can be made that after the optimization, the firewall can to a certain degree effectively reduce the filtering response time of the package.
出处
《现代计算机》
2007年第12期66-68,共3页
Modern Computer
基金
广西自治区科技厅项目(桂科攻0537020-5A)
关键词
防火墙
包过滤
规则组织
响应延时
Firewall
the Package to Filter
the Rule Organization
Response Delay