[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: ACL optimization



José M. Fandiño wrote:

As a curiosity, servers matched by the first rules are about 5 or 6 times
faster to response than servers matched by last rules. I thought that the ACL evaluation time will be uniform because the whole set of rules
would be evaluated. this makes sense to someone?


5 times sounds a lot; but access rules are evaluated only up to a match of the <what> clause, unless a <control> is specified (e.g. e "break"). So, in those cases ACL checking is particularly heavy, I 'd expect some overhead for operations that result in evaluatting all of them compared to those that result in evaluating only the first rules.

p.


SysNet - via Dossi,8 27100 Pavia Tel: +390382573859 Fax: +390382476497