View Single Post
  #2 (permalink)  
Old 2006-03-28
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: SmartDefense Update CPAI-2006-033 / CVE-2006-1359

Cisco is blaming CheckPoint in competitive cheat sheet in low performance. As far as i remember Cisco states that Checkpoint with SmartDefence enabled can do only 4Mbps of "real world traffic" (this is the traffic mixture Cisco with a help of third part consultants discover and use for simulations and tests) on a maximum equipped hardware!!! Cisco using this numbers aggresivly. For me this is unbelievable.
Checkpoint is stating that all protocol inspections (e.g. HTTP inspection for example) are moved from Security Servers to the kernel and are "very fast". But I think such complex inspections cam move this inspections back to the Security Servers :|

We have done in home performance testing some time ago. We have used eval version of the Ixia traffic generator. We have found no difference between to hosts routed over Cisco Catalyst 3550 Switch and the same hosts routed over CheckPoint NGX SPLAT (near Gig performance). Undoubtedly our test environment and traffic patterns was pretty simple.
Reply With Quote