Great Circle Associates Firewalls
(April 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall failure modes (was Re: performance)
From: Frank Wortner <frank @ prodigy . com>
Date: Tue, 25 Apr 1995 14:38:31 -0400 (EDT)
To: Firewalls <firewalls @ greatcircle . com>
In-reply-to: <Pine . 3 . 89 . 9504251010 . B4230-0100000-0100000 @ gatekeeper . ddp . state . me . us>

For what it's worth, there are some basic questions I'd like to have 
answered about a firewall product.

How many HTTP, FTP or what-have-u-P sessions can it sustain with some 
reasonable level of throughput?

Even assuming that it does failsafe, at what point does it do so?

If it doesn't failsafe, what does happen?

What are the warning signs of impending failure or resource exhaustion?

What parameters should we watch for signs of capacity exhaustion?

When do individual components, such as logging subsystems reach 
capacity?  What happens then:  do they fail, do they throttle response ...?

There are others, but these are just the ones that come to mind.  The 
response and failure under load information are particularly relevant to 
a site like this,  where we have to sustain litterally thousands of 
WWW/FTP/GOPHER sessions at once.

There is useful knowlege to be gained here --- IFF less time is spent 
arguing and more time spent testing, measuring, and publishing!

					Frank

--
"Outside of a dog, a book is a man's best friend;
 inside of a dog, it's too dark to read."  -- Groucho Marx



References:
Indexed By Date Previous: SUSCRIBE
From: <Kelly_Lawrence @ aa-resg-dc . ccmail . compuserve . com>
Next: [no subject]
From: David M Funk <FUNKD @ cna . org>
Indexed By Thread Previous: Re: Firewall failure modes (was Re: performance)
From: David Miller <isdmill @ gatekeeper . ddp . state . me . us>
Next: Re: Firewall failure modes (was Re: performance)
From: "Marcus J. Ranum" <mjr @ tis . com>

Google
 
Search Internet Search www.greatcircle.com