Networking Forums

Networking Forums > Computer Networking > Linux Networking > firewall performance question

Reply
Thread Tools Display Modes

firewall performance question

 
 
Ramses v. p.
Guest
Posts: n/a

 
      12-10-2004, 10:07 AM
Hello,

Here at the office I am thinking of kicking the current cisco router out
of the window after 10 years. We have a 10 MBit line and need a good
firewall/router/masquerader to get access to the net.

Wil a 2400MHz xeon with 1 gig memory and scsi discs be enough to route
500 employees using OSPF?

Thanks
ramses
 
Reply With Quote
 
 
 
 
Michael Heiming
Guest
Posts: n/a

 
      12-10-2004, 04:57 PM
In comp.os.linux.networking Ramses v. p. <(E-Mail Removed)>:
> Hello,


> Here at the office I am thinking of kicking the current cisco router out
> of the window after 10 years. We have a 10 MBit line and need a good
> firewall/router/masquerader to get access to the net.


> Wil a 2400MHz xeon with 1 gig memory and scsi discs be enough to route
> 500 employees using OSPF?


Completely OTT the box, a much slower box should be able to
handle this easily, in runlevel 3.

I'd run squid in addition on the box, to speed up internet
access for users.

--
Michael Heiming (X-PGP-Sig > GPG-Key ID: EDD27B94)
mail: echo (E-Mail Removed) | perl -pe 'y/a-z/n-za-m/'
#bofh excuse 84: Someone is standing on the ethernet cable,
causing a kink in the cable
 
Reply With Quote
 
Alexander Clouter
Guest
Posts: n/a

 
      12-10-2004, 09:49 PM
On 2004-12-10, Ramses v. p. <(E-Mail Removed)> wrote:
>
> Wil a 2400MHz xeon with 1 gig memory and scsi discs be enough to route
> 500 employees using OSPF?
>

arf! And you plan on using the SCSI disks for what?

We have had in the past a box half the speed routing (BGP though) a
customer base at least an order of magnitude higher than that!

One thing I will suggest now, do *not* use connection tracking at all, no
stateful firewalls must take place; unless you _really_ know what you are
doing.

Cheers

Alex
 
Reply With Quote
 
Marcelo Rodrigues
Guest
Posts: n/a

 
      12-12-2004, 06:19 AM
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Ramses v. p. wrote:

> Here at the office I am thinking of kicking the current cisco router out
> of the window after 10 years. We have a 10 MBit line and need a good
> firewall/router/masquerader to get access to the net.
>
> Wil a 2400MHz xeon with 1 gig memory and scsi discs be enough to route
> 500 employees using OSPF?


If it will be only firewall, then no need to SCSI disks.

I don't know how much memory would tke 500 users, but I do believe 1 gig is
more than enough.

About horsepower... I have a samll router, doing firewall and NAT. When I
run the backup of the server it crosses the fireall, and is NATed. I can
make about 70 - 80 Mbit/s, sustained (it's a fast ethernet) with rsync. The
hardware is a K6 2 350, with 64 MB RAM.

[]s

- --
Newsgroups Shiva: Aprecie com moderação
www.shiva.eti.br

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBu/Ee977gajvh3yYRAvGFAJ448FHCU+/HeXc+T9B3dA5+3fO47QCeMIAP
0iddhKMU9WTl8U//LZnRHi4=
=3f0c
-----END PGP SIGNATURE-----
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
LINUX/shorewall firewall to firewall VPN question sundog@mountaindogs.net Linux Networking 3 03-14-2006 04:04 PM
question about 802.11b vs. 802.11g performance Jeff Fawcett Wireless Internet 3 08-08-2004 03:59 PM
3Com Wireless 11g Access Point (Performance Question) Lee J. Moore Broadband 9 01-04-2004 11:11 PM
a question of internet performance Ward Taylor Linux Networking 4 10-15-2003 01:33 AM
tcp question (performance over high latency networks) mark smith Linux Networking 0 07-03-2003 09:00 PM



1 2 3 4 5 6 7 8 9 10 11