Drop packet under heavy load incoming connections, also to ip's set as allowed

here the down.

Hello.
Whiteout IP fire, I have reached 900 Mbps out with 420 viewers for 12 hours without problems.

Anyone can advice me any simple interface firewall like ipfire to run without lag with proxmox?

How can you run this without a firewall?

As I said, you seem to be running a more complex setup there. The hypervisor will be your bottleneck.

It will require more information on your setup and workload in order to remove that.

1 Like

Hi. I used the embed proxmox hypervisor firewall opening only the public stream port.
Others ports where the VPS receive my encoded video stream are locked to my source static IP. The only world visibile port is the stream port where the viewers connect to see the live video.

Inside the stream software platform i deny access to all non Italy ip’s and with hotlink protection and play locked to the specified domain , generating a time scheduled string code to append to the stream url.

In this way the only visibile port is the stream port, only italian ip can try to see the stream, the stream is webpage password protected and the video stream link player expire every 60 second from the first time compiled page.

It’s like to use the geo ip block of ipfire and lock incoming connections only for a specified source ip.

https://pve.proxmox.com/wiki/Firewall

Also i have configured TCP BBR congestion control directly on the VPS

and enabled multiqueue to 8 cpu thread on the hypervisor for the VPS virtual ethernet card

it remains in the sense that if I could use ipfire for these situations, it would be great in order to better manage the security