Re: [fw-wiz] Firewall scaling

From: Mikael Olsson (mikael.olsson_at_clavister.com)
Date: 02/22/04

  • Next message: Subha: "Fw: Re: [fw-wiz] Firewall scaling"
    To: Tim Chettle <Tim.Chettle@orange.net>
    Date: Sun, 22 Feb 2004 15:23:09 +0100
    
    

    Tim Chettle wrote:
    >
    > what view do you all have to Firewall Scaling / performance
    >
    > I have a requirement for a Gig capable firewall capable of handling
    > approx 100k sessions concurrently varying packet sizes and i am unsure
    > of the session setup rate.
    >
    > I would appreciate the lists views on factors to look for in terms of
    > performance indicators and experience's

    I'm unsure what you're asking for here, but given your actual
    requirements, I thought I'd give you my view of what you should
    be shopping for in terms of raw numbers.

    If by "gig capable" you mean "capable of forwarding 1 gigabit/s
    in each direction", you need to double your numbers and aim for
    something that claims to handle 4 gbps/s. The reason is that
    nearly all throughput figures list throughput for full packet
    sizes. So: rule of thumb: double your throughput figures,
    unless you know for a fact that the numbers presented are
    mixed packet size figures.

    For state table size: if your 100k connections is your expected
    normal usage, you need to guard against temporary floods to
    some extent, i.e. worm outbreaks such as SQL slammer. Or, heck,
    forget about worms, a room full of Unreal Tournament players
    can flood your state table by just refreshing their server
    lists at the same time.

    I'd recommend that you over dimension your state table by at
    least a factor of three, so you should be shopping for something
    with a state table size of at least 300k connections. This way,
    the firewall has a better chance of dropping unwanted connections
    when the state table does fill up.

    Actually, all this is just sensible engineering that has been
    applied to all forms of construction for oodles of years --
    it's just something that we sometimes forget in network
    engineering.

    [disclaimer: i work for a company that manufactures firewalls, so
    for all you know, I could be flat out lying about firewall sizing
    just to get you to buy a bigger box :) ]

    -- 
    Mikael Olsson, Clavister AB
    Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
    Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
    Fax: +46 (0)660 122 50       WWW: http://www.clavister.com
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Subha: "Fw: Re: [fw-wiz] Firewall scaling"

    Relevant Pages

    • Re: Advice on which FreeBSD firewall package to choose.
      ... but from other lists I get the sense the pf is the best option ... We use redundant 5-port pfSense boxes for our firewall - works quite ... Software-based VPN connections out from both the Inside LAN and Wireless ...
      (freebsd-questions)
    • Re: Question(s) default firewall in Fedora
      ... There is no service "firewall", ... Input rules affect connections coming in to the network. ... If you want to set rules by hand, learn about iptables. ... read messages from the public lists. ...
      (Fedora)
    • Re: How to get rid of persistent virus programs.
      ... > Long query about dealing with Pesky trojans and spyware ... > At least something like before and after lists, ... I'll mainly work around Windows XP, as that is what the bulk of this ... Why you should use a computer firewall.. ...
      (microsoft.public.windowsxp.help_and_support)
    • [fw-wiz] Re: Best Practices
      ... people separate network level (firewall, proxy, router acls, etc.) from ... so a security policy might be a base best practice;> Only part ... best practices aren't as much about giving people specific lists ... practices, I know I have other things to do and I assume you and Paul do ...
      (Firewall-Wizards)
    • RE: Looking for ipfw info.
      ... > legacy stateless rules when only stateful rules should be used to ... Yes for an firewall without an lan behind it ... You can access this lists archives at ... Then search the questions list archives at ...
      (freebsd-questions)