Answers:
引用来自 Jan Engelhardt
The theoretical upper limit of maximum number of rules for a 32-bit
environment would be somewhere around 38 million, but you could also
construct a rule that is so crowded with matches that even it won't
fit, so the lower limit of max rules is 0.
service iptables status | wc -l
给我112373
。64位centos 6,具有96个RAM。添加更多规则甚至重新加载该数量没有问题。
根据linuxquestions.org的说法,在一台32位计算机上,IPTables将支持大约25,000条规则。除此之外,尤其是从27,000起,事情开始变得不稳定。