[Firehol-support] blocklists

Whit Blauvelt whit at transpect.com
Tue May 26 22:09:39 BST 2015

Hi Costa,

Since you've pushed ipsets so far, have you seen any noticable system
performance issues when there are thousands, or tens of thousands, of IPs in
your ipsets? On the one hand I'm thinking, "What a great idea. I'll just
blacklist all the IPs on the blacklists." On the other hand, there must be
some threshold where it becomes computationally expensive, and I don't have
the measure of that.



