Re: Is Linux based Gateway/Firewall feasible

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Le jeu 08/07/2004 à 14:10, Sudheer Divakaran a écrit :
> I'm asking this because one guy told me that my decision to go for a 
> Linux based solution is a wrong one and it can never match the 
> performance of hardware based Routers.

While this statement is not true regarding low end Cisco products : my
home "ye old good" P233MMX performs better at routing/firewall than a
Cisco 827 router with IOS Firewall. Not mentioning price... Stressed, I
got 50Mbps total passthrough using DLink quad ethernet adapter, router
optimize kernel and ratherly clean ruleset, what is largely overperforms
my needs...

Now, one can tell you that a Cisco 7200 serie will perform far better
than a PC architectured solution based on Linux, which will probably be
true. But, the thing you should consider first is whether you need this
performance or not. I mean I could plug a 7200 on my home LAN, with
gigabit interface, connected to a 2950 switch and so on. It will perform
far better than my Linux box. But, in my context which is 5Mbps ADSL
link, 3 Wifi 54g laptops and 1 box, I certainly don't need this
overpowerful and overpriced solution.

Now you can stress your Linux box to bench it, and see if it offers
bandwidth and latency you need now, and fits your future evolution
plans. And don't forget a high end PC with PCI 64bits gigabit adapter is
often cheaper than most Cisco stuff...

Finally, you have to take in account the fact that a Linux based
solution is de facto full featured, as with stock 2.6 kernel, you have :

	. routing
	. advanded policy routing
	. QoS
	. stateful firewalling from layer 2 to layer 5
	. 802.3ad bonding (see Cisco Etherchannel)
	. 802.1q VLAN support
	. etc...

Which is not necessarily the case of Cisco routers with stock IOS, not
mentionning the fact that some Cisco routers cannot be shipped with all
available features because of a too small Flash/RAM amount.


-- 
http://www.netexit.com/~sid/
PGP KeyID: 157E98EE FingerPrint: FA62226DA9E72FA8AECAA240008B480E157E98EE
>> Hi! I'm your friendly neighbourhood signature virus.
>> Copy me to your signature file and help me spread!



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux