Community discussions

MikroTik App
 
cartes
newbie
Topic Author
Posts: 41
Joined: Fri Oct 12, 2007 12:23 am

Largest Matchable Address List

Sat Feb 20, 2010 10:56 pm

Hi,

I have created a rule that puts some matching IP addresses on an address list, then use the list to do other stuff.

However, during the day, I have seen that the rule that "matches" the address list (using it in the scr-address-list field), does not seem to work, and the next rule comes into play.

My list can get pretty big, around 7 - 8k entries, and I was wondering if there was any limit on how large an address list is matchable by a rule in the firewall filter / nat / mangle rules.

Can someone please clarify?
 
changeip
Forum Guru
Forum Guru
Posts: 3830
Joined: Fri May 28, 2004 5:22 pm

Re: Largest Matchable Address List

Sat Feb 20, 2010 11:29 pm

there was known issues with older versions having these problems. are you on the latest RouterOS version?

I have a list with 100,000 entries almost and it hasn't been an issue. I am very selective about what gets matched on that list however, not every single packet gets checked.
 
cartes
newbie
Topic Author
Posts: 41
Joined: Fri Oct 12, 2007 12:23 am

Re: Largest Matchable Address List

Sun Feb 21, 2010 12:44 am

Thanx for the quick response!

I'm using RouterOS 3.6. Is that known to have that issue?

I don't want to match every packet with that list also, but when I tried to do this:

/ip fir man add chain=prerouting src-address-list=ggnn action=jump jump-target=mychain
/ip fir man add chain=mychain src-address-list=gx action=return
/ip fir man add chain=mychain action=add-src-to-address-list address-list=gx address-list-timeout=12h

It keeps working, but after a while, as the list "gx" grows, at some point it just stops matching, and passes to the next rule. I've not yet been able to figure out where is that "point of not working" yet.

I've not upgrade RouterOS for a while, as new versions seems to have new bugs. The most notorious was the CPU timing problems when I upgraded to 3.13 and subsequently upto 3.17 (then gave up).
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8709
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: Largest Matchable Address List

Sun Feb 21, 2010 1:26 am

I'm using RouterOS 3.6. Is that known to have that issue?
What's new in 3.17:

*) fixed /ip firewall address-list;
it's exactly what you need. it was fixed at November 19th, 2008 =) I still remember those days - it took about 5 weeks to locate that nasty bug, but we did it!
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8709
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: Largest Matchable Address List

Sun Feb 21, 2010 1:27 am

The most notorious was the CPU timing problems when I upgraded to 3.13 and subsequently upto 3.17 (then gave up).
huh, one more step - and
What's new in 3.18:

*) updated drivers & kernel - fixed fast clock issue on x86;
:D
 
cartes
newbie
Topic Author
Posts: 41
Joined: Fri Oct 12, 2007 12:23 am

Re: Largest Matchable Address List

Sun Feb 21, 2010 1:35 am

Aah... You're the man! :)

Do you recommend I move to the latest 4.5? Or stick with 3.30? I'm running a production system consisting of 24 MTs, of which 3 have quite a complex setup (lots of rules, queues, etc).
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8709
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: Largest Matchable Address List

Sun Feb 21, 2010 1:40 am

for VPN server we're still using 3.28 + routing-test. that's not far from v4 =)

Who is online

Users browsing this forum: CGGXANNX, jvanhambelgium, mkx and 109 guests