Имеем следующий набор правил:
Chain FORWARD (policy ACCEPT 579K packets, 2016M bytes)
pkts bytes target prot opt in out source destination
0 0 CONNMARK all -- any any anywhere anywhere STRING match "%D0%9C%D1%83%D1%80%D0%B0%D0%B4+%D0%A0%D0%B0%D0%B3%D0%B8%D0%BC%D0%BE%D0%B2" ALGO name kmp TO 65535 CONNMARK xset 0x2/0xfe
0 0 CONNMARK tcp -- any any anywhere anywhere STRING match "CONNECT " ALGO name kmp TO 65535 STRING match "Proxy-Connection:" ALGO name kmp TO 65535 CONNMARK xset 0x2/0xfe
0 0 REJECT tcp -- any any nbrd.local/16 anywhere match-set tor dst reject-with tcp-reset
0 0 CONNMARK tcp -- any any anywhere anywhere STRING match "GET http://" ALGO name bm TO 65535 CONNMARK xset 0x2/0xfe
0 0 REJECT tcp -- any any anywhere anywhere STRING match "HTTP/" ALGO name bm TO 65535 connmark match 0x2/0xfe reject-with tcp-reset
Chain OUTPUT (policy ACCEPT 729 packets, 219K bytes)
pkts bytes target prot opt in out source destination
Без правил да 1.80Gbps.
Вопрос? Как ускорить connmark и iptables в целом?