On Wed, 2004-06-02 at 15:54, Brett Simpson wrote: > We are a large organization, 3000 plus users, considering switching from Checkpoint FW1 to Iptables. I was wondering how many large organizations (1000 plus users) are using Iptables in a production environment? > > For those that are using Iptables and were previously using a commercial product what were your reasons for switching and what issues have you seen using Iptables? > > Thanks, > Brett I do not have any massive deployments yet but the ISCS project (http://iscs.sourceforge.net) is initially based upon iptables as the firewall and is targeted to large enterprise and carrier networks. We've not yet had the opportunity to stress it. We have placed iptables based firewalls on some client sites that are smaller than yours but very avid web users (large, international PR firm) and we've not had them break a sweat. They have never gone down. I'm looking forward to both the other responses and the day when I can say we have ISCS deployments numbering thousands of gateways and many tens of thousands of users - John -- Open Source Development Corporation Financially sustainable open source development http://www.opensourcedevelopmentcorp.com