Replies: 1 comment
-
Hi @ouvaa , thank you for your interest to Tempesta FW. Really, this is a frequently asked question (e.g. #1908 or #1898). The answer is that Tempesta FW involves a lot (really a lot!) of logic to process TLS, HTTP, advanced data structures and so on. All this logic would be hard to implement in eBPF, even w/o limitation code size - there are other verifier limitations. However, we do have logic, which is developing in eBPF , e.g. volumetric DDoS protection #1048 and HTTP rules processing (HTTPtables, #102). |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
possible to transition to ebpf / af_xdp for version 1 or something? not trying to be funny or troll but since kernel patch is needed, might as well just increase the number of instructions for ebpf and just do ebpf since perf is what is being pushed here.
right? also ebpf / af_xdp is cleaner
Beta Was this translation helpful? Give feedback.
All reactions