Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall Speed contests = Bad thing
From: sangster @ reston . ans . net (Paul Sangster)
Date: Mon, 21 Jul 1997 09:06:45 -0400 (EDT)
To: rick @ tis . com (Rick Murphy)
Cc: marc @ sniff . ct-net . de, stoutb @ pios . com, firewalls @ GreatCircle . COM
In-reply-to: <3 . 0 . 1 . 32 . 19970720001116 . 00707a50 @ pop . rv . tis . com> from "Rick Murphy" at Jul 20, 97 00:11:16 am

-----BEGIN PGP SIGNED MESSAGE-----

> 
> At 08:14 PM 7/17/97 +0000, marc @
 sniff .
 ct-net .
 de wrote:
> >One reason, why DataComm was doing this stress test is the upcomming
> >need for internal firewalls. 
> 
> It's too bad the test was so unrepresentative of real-world IP traffic.
> More than 90% of the traffic was FTP, the rest HTTP. Sorta backwards from
> the real world..

I believe this is backwards, 90% was HTTP and the remainder was FTP (via
ftp URLs I believe).  I viewed this test as very WWW-centric which in
many ways is a good performance gauge because of the impact on the firewall
by heavy loads of HTTP (AKA TCP) connections.  IMHO, this is much more 
telling than worrying about the number of bits passed using something
like FTP.

I frequently hear people ask "how big of a firewall do I need to protect
my T1 line".  My experience (at least with our product) is that the 
connection speed/firewall throughput is rarely the most challenging factor
(can you say "100Mbps ethernet" :-)). Normally, its the traffic mix 
(particularly HTTP and SMTP) and usage pattern (load spikes) drive that
drive the hardware platform.  So the Data Comm's performance section is 
useful to feed one data point (benchmark WWW performance for a particular 
hardware configuration) when evaluating firewalls.  

It should be mentioned that at least this year's Data Comm. article (unlike 
the previous one) focused on more than just performance.  I wish the other 
trade rags doing comparisons of firewall actually looked at the products 
and not just their marketing literature before publishing their opinions 
for the masses ;-).

Paul

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQB1AwUBM9Ne5ArwW0NaS5JJAQGl5AL+ON6HYM70ua2uUV06TLtsI+iofsdnVE5l
FcMJMv7yuCQ+37R6O35JeND+/KGxbAdeJX71/HK/cck6QiVdJS1SVkmo4z4YPLmo
sYFvzheec1ncL6WrxKS4FVxwGWwbqEOj
=kgZG
-----END PGP SIGNATURE-----


Follow-Ups:
References:
Indexed By Date Previous: How to communicate with two network Card
From: wei @ prestigein . com (wei hao)
Next: filtering out browser downloads?
From: Dan Crowson <dcrowson @ cmsc . com>
Indexed By Thread Previous: Re: Firewall Speed contests = Bad thing
From: Rick Murphy <rick @ tis . com>
Next: Re: Firewall Speed contests = Bad thing
From: Frank Darden <fdarden @ locked . com>

Google
 
Search Internet Search www.greatcircle.com