IP masquerade limits?

Larry McVoy (lm@bitmover.com)
Thu, 09 Jul 1998 14:42:32 -0600


Does ayone have any experience on the maximum number of hosts that can
be masqueraded with one machine? Assuming that you don't run out of CPU
(which is a pretty safe assumption if you are behind anything from 10Mbit
down, right?), then it is a question of running out of ports, since each
IP addr being spoofed is an additional port on the masquerading machine.

Given 60K ports or so, if you assume everyone is netscaping away, seems
like the limit is probably somewhere in the 5K active users range. Am I
even close?

Another way to ask this: what's the most hosts you've ever seen behind
a masquerading firewall?

Thanks,

--lm

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu