Firewall Wizards mailing list archives

Re: Firewall Throughput


From: Rick Murphy <rmurphy () mitre org>
Date: Wed, 06 Sep 2000 07:43:04 -0400

At 10:25 AM 9/5/2000 -0500, Benson Hill wrote:
Of course, both companies claim their solution is the best.
Cisco says they are faster, CheckPoint says that's true only
for certain types of traffic.

Does anyone have any reliable information comparing the
throughput of the two products?

Before you can get a good answer to that question, you'll need to refine the question. Define "throughput" - number of connections per second, bytes per second, etc.. What protocols are you planning to measure? Do you want to use filtering that requires using a Firewall-1 security server? If so, make sure you measure that way. Checkpoint allows the use of "fastmode" for TCP services; that's a static 'established' filter - make sure your measurements aren't using that mode unless you're willing to take the risk.

There are also bigger questions, like what form of user authentication you're planning to use and whether the products support it, whether or not you want to virus scan e-mail, etc. Define your entire requirements set, don't try to concentrate on one facet of the two products.
        -Rick



_______________________________________________
Firewall-wizards mailing list
Firewall-wizards () nfr net
http://www.nfr.net/mailman/listinfo/firewall-wizards


Current thread: