From mboxrd@z Thu Jan 1 00:00:00 1970 From: Askar Subject: ram and processor cycles for a firewall machine Date: Fri, 1 Oct 2004 12:35:15 +0600 Sender: netfilter-bounces@lists.netfilter.org Message-ID: Reply-To: Askar Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: netfilter-bounces@lists.netfilter.org Content-Type: text/plain; charset="us-ascii" To: netfilter hi all, im in the process of changing my fw machine for that atm im simulating and testing. I got a very fair question 1) How much RAM and and processor would be best for moderate firewall box? Unfortunatly currently my company running the fw on a P-III 500MHz with 128MB of RAM. I am wondering if I change to default DROP things (atm its default ACCEPT) aren't these specification kinda makes problem? right now 75 users online the /proc/net/ip_conntrack shows egrep 'ESTABLISHED|ASSURED' /proc/net/ip_conntrack | wc -l 4888 cat /proc/net/ip_conntrack | wc -l 6511 well these number would probably little higher when 120 users online. Is my current fw machine specs adequate for such ip_conntrack load? regards Askar (after bouncing head on desk for days trying to get mine working, I'll make your life a little easier)