Re: What does VPN throughput mean?

From: Dave (ocorphousing1n0spam_at_woh.rr.com)
Date: 12/19/03


Date: Fri, 19 Dec 2003 11:48:33 GMT


"Leythos" <void@nowhere.com> wrote in message
news:MPG.1a4c01719c2d3795989f82@news-server.columbus.rr.com...
> In article <8bdf2d47.0312180925.6fe5aaa7@posting.google.com>,
> nospamj@i0ta.com says...
> > Greetings:
> >
> > We are having a struggle at work determining which firewall appliance
> > to purchase. The office has approximately 30 people with about 50
> > more working in the field and is attached to the Internet via a T1. I
> > am the Network Administrator, so naturally I would like something that
> > is easy to administer, secure, has some IDS, and other features. So,
> > I picked out a nice, feature rich Fortigate 100. According to it's
> > literature it has these performance characteristics:
> > ------------------------------------
> > FG100:
> > Concurrent Sessions = 200K
> > New Sessions/second = 4K
> > Firewall Throughput (Mbps) = 95
> > 168-bit Triple-DES Throughput (Mbps) = 25
> > Concurrent Users = 10/Unlim
> > ------------------------------------
> [snip]
> > Cisco's website:
> > ------------------------------------
> > Cleartext throughput: 188 Mbps
> > Concurrent connections: 130,000
> > 168-bit 3DES IPsec VPN throughput: Up to 140 Mbps with VAC+ or 63 Mbps
> > with VAC
> > 128-bit AES IPsec VPN throughput: Up to 135 Mbps with VAC+
> > 256-bit AES IPsec VPN throughput: Up to 140 Mbps with VAC+
> > Simultaneous VPN tunnels: 2000
> > ------------------------------------
>
> The PIX515E with VAC (not VAC+) is almost $5,500 from CDW.
> The Fortigate 100 is almost $2000 from firewalldepot.com
>
> You are not looking at the same class of firewalls here - the PIX is way
> more firewall than the Fortigate.
>
> The WatchGuard Firebox III-1000 is about $4,800 and is faster than PIX
> without VAC+
>
> The specs are as follows:
> PERFORMANCE
> Branch Office VPNs 2000¹
> Mobile User VPNs 2000¹
> Packet Filter Throughput 200 Mbps
> VPN Throughput 75 Mbps
> HTTP Proxy Throughput 94 Mbps
> Authenticated Users 5000
> User License Unlimited
>
> The WatchGuard V60 is also faster than the PIC515E/VAC (not VAC+)
>
> PERFORMANCE
> Firewall Throughput 200 Mbps
> VPN Throughput 100 Mbps
> Branch Office VPNs 400*
> Mobile User VPNs 400*
> User License Unlimited
> *The total number of Branch Office plus Mobile User VPN tunnels.
>
> While the VPN performance far exceeds the T1 you will have, you may find
> that you need that type of performance in order to decode at the
> hardware level in order to keep the line speed up - you don't want the
> firewall do be bogged down doing encrypting and decrypting.
>
> I have no experience with Fortigate, so I would not install them unless
> they provided a 1 month demo in our environment for free.
>
>
> --
> --
> spamfree999@rrohio.com
> (Remove 999 to reply to me)

http://watchguard.links.channelintelligence.com/pages/prices.asp?sSKU=WG31000

If the link above works, the 1000 is around $2250.00 US. It includes 1 year
of "LiveSecurity" which is a subscription for support. After the 1 year,
its ~$1000.00/year to renew but the box will still work even if you don't
renew.



Relevant Pages

  • Re: What does VPN throughput mean?
    ... more firewall than the Fortigate. ... Branch Office VPNs 2000¹ ... Packet Filter Throughput 200 Mbps ...
    (comp.security.firewalls)
  • Re: help file transfer
    ... exact same message and I'm only trying to send a photo. ... believe there is a Firewall setting somewhere that needs to be ... > network administrator or Internet service provider. ... >> MSN Messenger File Transfer from the USA to Belgium. ...
    (microsoft.public.windowsxp.messenger)
  • Re: network administrator
    ... Conflicts start where information lacks. ... Suggested posting do's/don'ts: http://www.dts-l.org/goodpost.htm ... You can only turn off the network administrator by offending him or her. ... If the popup message is during boot don't fret, it's a common message if security is checked before the firewall is actually enabled. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Hacking into firewall
    ... > try and access the sites which we are denied access into?? ... Ask your network administrator the following questions, ... What type of network operating system is used to run the firewall? ...
    (microsoft.public.inetserver.iis.security)

Loading