CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've just added two more speakers!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2 Weeks Ago
cciesec2006 cciesec2006 is online now
Senior Member
 
Join Date: 2006-09-26
Posts: 527
cciesec2006 has an average reputation (10+)
Default Firewall Performance question

I have a pair of Sun X4200-M2 running NGx R65 2.6 kernel in Active/Standby
ClusterXL. These Sun boxes have 4GB RAM on each box. I have about 200
rules in the security policy with about 2000 objects.

I have 12 Dell Servers 2950-III, 8GB RAM with dual quad-core processors,
6 servers behind the firewalls and 6 servers outside of the firewall.
Everything is connected to a Cisco Catalyst 3750 24 ports 10/100/1000.

According to the diagram, when I fired Iperf client x, y and z to hit iperf server
1, 2 and 3, respectively, I could see the Active firewall handle 1Gbps
throughput. That's the
good part.

However, when I fire Iperf client 4, 5 and 6 to hit Iperf servers A, B and C, I
could see the traffics on the External interface of the Active firewall
dropped to 500Mbps received and 700Mbps transmitted. I know that
WITHOUT firewalls, my catalyst can handle > 1Gbps easily both way.

My question is this: do these firewalls capable of handling >1Gbps
throughput of is it just a marketing ploy by Checkpoint? I am not
interested in connection per second, only in firewall throughput.
From what I can observe, the Sun X4200-M2 can not handle >1Gbps
throughput.

Am I wrong here?
Attached Thumbnails
firewall-performance-question-iperf.jpg  
Reply With Quote
  #2 (permalink)  
Old 2 Weeks Ago
chillyjim chillyjim is online now
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,509
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Firewall Performance question

There is a lot of things that can effect firewall throughput. My guess is that peak performance on a X4200 would be about 80% of the interface speed. After that point the firewall's rules and other processing come into play. There are a lot of tunning "tricks" to improve performance including the use of more interfaces (Yes this is a real PIA for most designs) and rule-base optimization with SecureXL.

I'm assuming this is on a lab environment, so to get a base line, load a gateway with Solaris X86 and enable routing to see how much throughput you have there (You can load a Linux build for this too if you know how).

Then try your test with one gateway and an "Any Any Accept No-log" rule. That will give you the baseline for the FW's throughput (This is also how all firewall throughput is reported, not just Check Point's).

As for can you get better than a Gbps through a X4200, yes if you have more than one pair of interfaces going.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 10:57.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0