Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: IP Filters?
From: Brian Mitchell <brian @ firehouse . net>
Date: Thu, 3 Jul 1997 15:00:20 -0400 (EDT)
To: Fernando da Silveira Montenegro <montenegro @ nutec . com . br>
Cc: Firewalls @ GreatCircle . COM
In-reply-to: <9707030835 . aa04683 @ canario . nutec . com . br>

On Thu, 3 Jul 1997, Fernando da Silveira Montenegro wrote:

>  Hello all!
> 
> What seems to be the general consensus on how many filtering rules one can
> configure on a router without imposing a noticeable performance penalty:
> 10? 50? 100?
> 
> I know it probably varies  wildly with the equipment you use (2501 x 7500,
> for instance), but is anybody running a Cisco 4000 with more than, say,
> 100 rules for each filter applied to an interface? The router has 8MB, and
> is talking two T1s (bonded, no multihoming).

If you do stuff like handle the most frequent packets first (say an
established entry as the first rule) you shouldnt have too much of a
performance problem. The key is getting the majority of packets evaluated
at the very beginning, leaving the somewhat unusual packets near the end.

> 
> We plan to tighten up our environment a bit (too many DoS attacks for our
> liking), and are considering also stricter filters on our terminal servers
> (PortMaster2 units from Livingston). Same question applies: how many
> filters on a 1MB PM2?
 
Denial of services attacks are essentially impossible to defeat. They will
always be there in one form or another.

Brian Mitchell                           brian @
 firehouse .
 net
"BSD code sucks. Of course, everything else sucks far more."
- Theo de Raadt





Follow-Ups:
References:
  • IP Filters?
    From: "Fernando da Silveira Montenegro" <montenegro @ nutec . com . br>
Indexed By Date Previous: Re: ICQ network
From: DECkedout <DECkedout @ hotmail . com>
Next: Re: global whois servers ??
From: Meenoo Shivdasani <meenoo @ tis . com>
Indexed By Thread Previous: Re: IP Filters?
From: Paul Ferguson <pferguso @ cisco . com>
Next: Re: IP Filters?
From: Ken Jones <kenj @ cayman . gblhorizon . com>

Google
 
Search Internet Search www.greatcircle.com