[fw-wiz] Large ecommerce site performance concerns

From: K M (fweng_at_mail.com)
Date: 10/21/03

  • Next message: Hugh Blandford: "Re: [fw-wiz] Request for Information: study of patching a certain IIS-vulnerability"
    To: firewall-wizards@honor.icsalabs.com
    Date: Tue, 21 Oct 2003 14:09:41 -0500
    
    

    I am attempting to add a firewall in front of a very large e-commerce site. I have purchased a pair of HA PIX 535s for this purpose.

    The site currently (without firewall) has approximately 200,000 concurrent sessions and about 200Mbps at it's peak hours.

    Nearly all of the traffic is standard port 80 web traffic (average packet size is about 550bytes).

    The PIX will NOT be performing any encrytpion.

    The access-list is approximately 180 rules long.

    There are approximately 10 dynamic nats and 100 static nats.

    I know the PIX can support up to 500,000 concurrent sessions and 1.7Gbps of firewall traffic. We appear to be well under these specs.

    My question is: In your opinions, will the PIX be able to handle this type of load?

    Thanks for the help

    -- 
    __________________________________________________________
    Sign-up for your own personalized E-mail at Mail.com
    http://www.mail.com/?sr=signup
    CareerBuilder.com has over 400,000 jobs. Be smarter about your job search
    http://corp.mail.com/careers
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Hugh Blandford: "Re: [fw-wiz] Request for Information: study of patching a certain IIS-vulnerability"

    Relevant Pages

    • Re: Kindly help me with this PIX problem
      ... If you have read the configuration that I posted, ... firewall configuration didn't change over many years and it did work ... PIX, our company cannot send or receive email. ... That command allows ssh to the PIX, ...
      (comp.dcom.sys.cisco)
    • Re: Firewall for laptops, corporation with 1,000 laptops
      ... I disagree completely that all you need is a PIX to protect your network, ... PIX does nothing to protect you from VPN ... alerting, which are essential to a firewall solution, are lacking.] ... the PIX firewall does nothing to protect a roaming laptop from ...
      (microsoft.public.security)
    • Re: Cisco PIX fixup protocol command
      ... The PIX is a stateful firewall and maintains state on ... The reason why a security evaluation might result in a recommendation to ... is no need to have the SMTP fixup enabled. ...
      (Security-Basics)
    • RE: Hardware Firewall vs Software Firewall
      ... Hardware Firewall vs Software Firewall ... will drive the price to the point where the PIX is more cost effective. ... on a router ACL unless you're using the CSPM, ...
      (Security-Basics)
    • RE: [fw-wiz] Skip the PDM
      ... PIX and CheckPoint and the PIX 501 is a real contender as a firewall to ... So to "speed things up" I tried using the PDM. ... DHCP pool starts at .2. ...
      (Firewall-Wizards)