Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: How fast/how many ports can Gauntlet support?
From: amolitor @ anubis . network . com (Andrew Molitor)
Date: Mon, 22 Jul 96 23:23:38 CDT
To: Firewalls @ greatcircle . com
Cc: firewalls-performance @ greatcircle . com

	My experience with the TIS fwtk (see it on V-ONE's web site:

http://www.v-one.com/pubs/perf/amolitor/html/fwallperf.html

	thanks, mjr) suggests that if what you're doing is shoveling
bulk data, a couple of ethernets worth should be no big deal. I was
able to get a few hundred Kbytes/sec through a 386SX25 with lousy
ethernet cards, and I cannot imagine that a 10x improvement using
a fast pentium and some good ethernet cards would be difficult.

	Packet rate is a little sticky on a proxy firewall since:

	1) the packet count on one side will only be approximately the
	   same as the other, at best, and may be quite a lot different
	   (many TCPs use bigger packets to 'local' hosts than to remote).

	2) most proxies are built on a kernel that will copy packets
	   around some, so bigger packets will go through it slower
	   than smaller ones.

	3) Probably lots of 2nd order effects from TCP timers interacting.


	I speculate that things do not become really interesting until
either you're in the 100Mbit range, for bulk data rates. If you're dealing
with thousands of users at once, each doing a handful of fiddly little
transactions every minute, things also become interesting.

		Andrew

Indexed By Date Previous: Firewalls BOF at USENIX Security Conference
From: Brent @ GreatCircle . COM (Brent Chapman)
Next: Encouragement of Service
From: Dave Horsfall <dave @ fgh . oz . au>
Indexed By Thread Previous: How fast/how many ports can Gauntlet support?
From: Bill Stout <bill . stout @ hidata . com>
Next: Firewalls BOF at USENIX Security Conference
From: Brent @ GreatCircle . COM (Brent Chapman)

Google
 
Search Internet Search www.greatcircle.com