Enabling Distributed Firewall on KVM impacts connection handling performance
book
Article ID: 331580
calendar_today
Updated On:
Products
VMware vDefend Firewall
Issue/Introduction
Symptoms: When establishing a large number of connections between virtual machines, you may experience these symptoms:
Netperf may report errors similar to:
shutdown_control: no response received errno 104
The issue seems to manifest itself when default firewall rules have been configured
With the default firewall rule configured, the issue do not manifest itself with a lighter load (For example: with 1 virtual machine x 64 sessions, or 8 virtual machines x 4 sessions)
The issue do not manifest itself if firewall rules are not configured (For example: Logical switches are put in the firewall exclusion list).
In the /var/log/syslog or /var/log/messages file, you see entries similar to: