RE: Poll on large sites that deploy Iptables.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Aldo Lagana wrote:
> First off - like AOL, IBM, etc - all use high-end probably cisco
> routers which do their firewalling - one cannot get the packet per
> second throughput they need without dedicated ASIC-based
> router/firewalls... 

Correct me if I'm wrong, but aren't (at least mid-sized) CISCO firewalls
based on X86's down to the PCI bus and Pentium derived processors? Even
Mid-grade routers are supplying VPN accelerator chips, but I think the
firewall code itself is stored in flash, executed like any other
programs. I doubt IOS uses a lot of hardware acceleration beyond the
CPU. Although I really don't know much since I haven't done much work on
them.

An example:
(http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_qanda_it
em09186a0080091b17.shtml)
Even the 535's only use PIII 1ghz



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux