Comment 2 for bug 1453264

Revision history for this message
Brian Haley (brian-haley) wrote : Re: iptables_manager can run very slowly when a large number of security group rules are present

Kevin - I also think the change you mentioned at the bar might help too - make a chain for a particular SG containing it's rules, then have jump rules from the instance-specific chain to each SG chain it belongs too. That's deeper surgery in the firewall code, but should be doable. I can work on that after the summit (call me a slacker for not doing it during the summit :)