Michael Buffer wrote:
I'm considering purchasing some firewall machines for my organization, and I am trying to decide whether a machine with multiple CPUs is worth the additional expense performance-wise (aside from being able to assign CPUs
??? I cannot believe this is even under consideration. Just how big is your organisation?
I run iptables firewalls on very modest machines, with single and dual T1 lines, and there is never any CPU load from the packet filtering nor the NAT. I don't have any really large sites, but I strongly suspect that iptables firewalling of very large sites could easily be handled by dumpster-grade equipment.
Of course with a budget like yours you'll want something new, which is better (we hope) for the physical reliability of the machine. A fast CPU is useful for a fast boot time to minimise down time in the event of problems. Otherwise, a waste.
Listen, I ran my home cable, with multiple simultaneous large downloads and 3-4 busy Web browsers on a 386. It never broke a sweat. This of course used ISA 10Mbit NIC's. It could have handled many times the load without problem.
Why did I decommision it? Electricity. I only had so many outlets, and I needed a machine to perform more complex tasks, so the firewall job got handed off to another machine, and the 386 was retired. Still here in case I need it again.
I need a new computer ATM. How about I build a firewall machine for you, and you send me that SMP super machine? ;)
-- mail to this address is discarded unless "/dev/rob0" or "not-spam" is in Subject: header