Hacker News new | ask | show | jobs
by rw- 5734 days ago
Consider using ipset. Your ruleset is very huge and slows down your netfilter...
1 comments

Thank you so much for the tip, I'll look at doing this.

FWIW though I have almost no traffic to these boxes, so I've never noticed any sort of performance issues.