CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Nortel ASF/NSF
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-31
Junior Member
 
Join Date: 2005-12-29
Posts: 19
Rep Power: 0
ngsud has an average reputation (10+)
Default Like a Nightmare to run NSF 6426

I don't know what Nortel claim it to be the one the best thruput firewall ... in my senario i am running with 7 of these cluster and all of them is not more than a dustbin for me . It's almost 1&1/2 year we integrated these firewall in our network by spending millions on this and i am still waiting for the resolution from Nortel for the problems which i am facing with these boxes .

1. VPN will Not work ( I am not saying , it's well documented in Nortel's release notes ) ------ This is true in may case unless i edited the conf file for the gateways it did worked , but this is not a resolution

2. Cluster in Load Sharing will not work for VPN ----- If you have major traffic in your network as i m having 10000 client at the back of this cluster and having 50 - 55 VPN site to Site tunnel and almost all the tunnels which are having the peer as Cisco , Netscreen and even checkpoint will drop off very frequently .

3. Latency ----- This is a major problem for me when i have the cpu utalized about 50 - 60 % the latency in LAN - DMZ - Extranet arm will go to 50 ms to 280 ms ...... ( i having NG AI R54 , NG FP3 running on solaris -- when they are 90 % i won't get even more than 3ms )

4. Intermitent Breaks ----- This is the very silent feature of this firewall you won't find this , i indeed relealised this after 1 year when for some reason there was frequent break in the connectivity for one of project and i routed the same traffic from my Solaris NG AI 54 Firewall and it worked no breaks at all .

5. Stability ----- One of the main reason for bringing these firewall in cluster mode was to have redundancy , but belive me it's not that easy to run Nortel Cluster


Over All the support for Nortel is terrable ( GNTS ) and with Checkpoint as well ...

If any one thinking to buy any of these read it and yes for some ppl it might seems to be a joke , but for me its like life going misreable .
Reply With Quote
  #2 (permalink)  
Old 2007-10-31
Senior Member
 
Join Date: 2007-06-04
Posts: 1,070
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Like a Nightmare to run NSF 6426

I believe if you just want a straight firewall and no VPN then they are quite good boxes, but personally I found them overly complicated and the Nokia's and Crossbeam X series have caught up in terms of performance.

They have there market place just certainly not a mainstream platform.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 06:29.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0