Great Circle Associates Firewalls
(May 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

From: jpf @ mig . com (Jack Flory)
Date: Sun, 8 May 1994 10:32:58 -0600
To: firewalls @ greatcircle . com

>
>First not all Internet connections are T1; some folks have faster lines.
>Second, not all firewalls are built between the Internet and an internal
>network; firewalls can and are being used to separate internal networks.
>
>Is screend running on a 486 "fast enough" to keep up at ethernet speed?
>

Yes!

>
>How about faster than a T1?
>

I use a PC with an AMD386/40 with 64 KB cache running NetBSD for the
firewall.  Note that this is an ISA bus machine.  Calculating out the
amount of time per packet from the CPU time used, I come up with about
2 MBytes / second.  Now, a machine based on a 50 MHz DX with 256 KB of
cache should be substantially faster.  Using a 3c579 Ethernet card on
an ESDI bus machine will double the Ethernet throughput.  Still, you
can't get 2 MBytes / second through a 1.25 MByte pipe.

So, if you look at the real throughput of a DS3, you should be able to
use a 50MHz DX ESDI bus PC to keep up with the traffic.



Indexed By Date Previous: Re: MBONE and Firewalls...
From: Geoff Mulligan <Geoffrey . Mulligan @ Eng . Sun . COM>
Next: Re: Screend ports (other than ULTRIX and BSD/386)?
From: jim @ Tadpole . COM (Jim Thompson)
Indexed By Thread Previous: Re: MBONE and Firewalls...
From: Geoff Mulligan <Geoffrey . Mulligan @ Eng . Sun . COM>
Next: more on TIS portscan and Cisco routers
From: reh @ cs . UMD . EDU (Richard Huddleston)

Google
 
Search Internet Search www.greatcircle.com