All of lore.kernel.org
 help / color / mirror / Atom feed
* Is Linux based Gateway/Firewall feasible
@ 2004-07-08 12:10 Sudheer Divakaran
  2004-07-08 12:55 ` Antony Stone
                   ` (3 more replies)
  0 siblings, 4 replies; 10+ messages in thread
From: Sudheer Divakaran @ 2004-07-08 12:10 UTC (permalink / raw)
  To: netfilter

Hi,

I've a local LAN consisting of about 150 machines.  I'm using a machine 
with Linux + IPTables  as the gateway machine which inturn connects to 
two different ISPs.  My question is can a Linux based machine match the 
performance of a hardware based routers provided by Cisco,... OR is my 
decision to go for a Linux based solution is a wrong one?.

Is there so much difference between these two solutions?

Can I achieve the same performance using a high end PC and Linux?

I'm asking this because one guy told me that my decision to go for a 
Linux based solution is a wrong one and it can never match the 
performance of hardware based Routers.

Thanks
Sudheer


^ permalink raw reply	[flat|nested] 10+ messages in thread
* RE: Is Linux based Gateway/Firewall feasible
@ 2004-07-08 13:21 Mike O
  2004-07-08 13:38 ` Antony Stone
  0 siblings, 1 reply; 10+ messages in thread
From: Mike O @ 2004-07-08 13:21 UTC (permalink / raw)
  To: netfilter

I'd like to chime in here considering I brought this topic up a few years 
ago. From a standpoint of routing data from one subnet to another with high 
speed serial interfaces etc.. nothing beats a cisco. Cisco routers have 
special ASIC(application specific intergrated circuits) that do nothing but 
routing and other features.

Now from a firewall standpoint, this is were Linux really shines. Cisco PIX 
firewalls are all based on Intel processors (even celeron) and PC 
architecture. So any machine with a 1ghz and gig of memory should out 
perform any PIX firewall. One thing PIX does bring to the table is failover 
but its expensive. I think any properly configured Linux cluster could give 
PIX failover a run for there money. Price a PIX 525 to a redundant Dell or 
HP slimline with Linux and I think you will be surprised.

-Mike


>From: Sudheer Divakaran <sudheer@svw.com>
>To: netfilter@lists.netfilter.org
>Subject: Is Linux based Gateway/Firewall feasible
>Date: Thu, 08 Jul 2004 17:40:33 +0530
>
>Hi,
>
>I've a local LAN consisting of about 150 machines.  I'm using a machine 
>with Linux + IPTables  as the gateway machine which inturn connects to two 
>different ISPs.  My question is can a Linux based machine match the 
>performance of a hardware based routers provided by Cisco,... OR is my 
>decision to go for a Linux based solution is a wrong one?.
>
>Is there so much difference between these two solutions?
>
>Can I achieve the same performance using a high end PC and Linux?
>
>I'm asking this because one guy told me that my decision to go for a Linux 
>based solution is a wrong one and it can never match the performance of 
>hardware based Routers.
>
>Thanks
>Sudheer
>




^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2004-07-09 12:35 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-07-08 12:10 Is Linux based Gateway/Firewall feasible Sudheer Divakaran
2004-07-08 12:55 ` Antony Stone
2004-07-08 14:05 ` Marco Colombo
2004-07-08 14:30   ` Sudheer Divakaran
2004-07-09  7:46     ` Cedric Blancher
2004-07-09 12:35       ` Marco Colombo
2004-07-08 14:43 ` Cedric Blancher
2004-07-09  0:38 ` Daniel F. Chief Security Engineer -
  -- strict thread matches above, loose matches on Subject: below --
2004-07-08 13:21 Mike O
2004-07-08 13:38 ` Antony Stone

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.