login
Header Space

 
 

Re: PF Congestion and state table question

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Date: Friday, May 9, 2008 - 9:51 am

Thanks for the hints. I've replied the questions below.

I was still wondering what could be considered "maximum" session 
concurrency that I could expect, with various hardware combinations? Is 
anyone that can tell me if it could be feasible with OpenBSD and better 
hardware? Even if we have to move to a different platform than i386, 
like maybe a Sun Fire T1000, as I don't see that as being a problem if 
it solves our issues. What we would like most if possible is to find 
something that could scale in the million concurrent sessions, but with 
a couple of thousands of new sessions per second. I know it's something 
very hardware demanding and even most enterprise class firewalls like 
Juniper and Fortinet don't scale much more than a million even on their 
higher end models, so that's why I'm curious as to what I could expect a 
PF setup to scale.

Thanks again,
Steve Johnson

Stuart Henderson wrote:
Mostly on the outside, but it was a "nice to have". I'll test to see if 
it helps a lot by just scrubbing in on the outside interface.
Yes, I am at the moment. However, it's the default gateway interface and 
so I can't really skip filtering on that interface. I'll try skipping on 
the inside interface, since the traffic will have already been validated 
and see if that changes much. I'm also trying to just skip session based 
filtering on that service as well, since it's one of the first pass 
quick rule and see if it helps. I was still seeing a bit of congestion 
though.
Good to know, thought most people didn't want to have too much stuff 
pasted in the emails.
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: PF Congestion and state table question, Stuart Henderson, (Thu May 8, 7:13 pm)
Re: PF Congestion and state table question, Steve Johnson, (Fri May 9, 9:51 am)
Re: PF Congestion and state table question, Jordi Espasa Clofent, (Sat May 10, 5:13 am)
Re: PF Congestion and state table question, Steve Johnson, (Sat May 10, 8:29 am)
Re: PF Congestion and state table question, Henning Brauer, (Sun May 11, 12:44 am)
Re: PF Congestion and state table question, Steve Johnson, (Sun May 11, 1:04 pm)
Re: PF Congestion and state table question, Henning Brauer, (Sun May 11, 7:31 pm)
Re: PF Congestion and state table question, Jordi Espasa Clofent, (Mon May 12, 3:44 am)
Re: PF Congestion and state table question, Henning Brauer, (Tue May 13, 5:57 am)
Re: PF Congestion and state table question, Jordi Espasa Clofent, (Tue May 13, 8:01 am)
Re: PF Congestion and state table question, Henning Brauer, (Tue May 13, 11:00 am)
speck-geostationary