kearton Posted October 15, 2015 Posted October 15, 2015 I've heard some interesting comments (from an engineer from an IT company (who isn't on EduGeek as far as I know), so it may just have been sales speak to big up their preferred product?) about the increasing need for a wirespeed UTM, in preference to alternatives like Smoothwall, Sophos, etc... They claimed they're seeing lots of problems with some customers seeing a "stutter effect" and slowdown in performance with non-wirespeed products, especially where the customer has a HEAVY reliance on Cloud technologies... They said there were only 3 wirespeed products on the market at present - Juniper, Palo Alto and FortiGate. I'd be very interested to hear everyone elses thoughts/opinions/experiences on this? Thanks in advance
Opendium_Steve Posted October 15, 2015 Posted October 15, 2015 I'm not sure what is meant by "wirespeed" in this context. As an example, if you have a 100Mbps internet connection connected to a 1Gbps LAN, your filter only needs to be capable of handling 100Mbps of throughput, unless you're also using it to filter traffic within the LAN, instead of just internet traffic. So if by "wirespeed" they mean that your filter should be able to handle the gigabit network, even though your internet connection is only 100Mbps, that sounds nuts to me and a complete waste of money. The amount of throughput a filter can handle isn't a completely trivial number to come up with either because it depends on usage patterns. For example, our web filter will examine the web address you're connecting to, HTTP headers and analyse the start of the content (i.e. once its determined that you're downloading a massive non-text file, it will stop trying to do text analysis on it), generate SSL certificates, etc; this means that the filter has to do a lot of work at the start of each HTTP request, but then the work-load goes down while it handles the rest of the download. So lots of small web requests will require far more processing than a few large downloads. I think latency is probably a more important factor than raw throughput. But that's affected by a great many different factors - the majority of the "slow internet" problems we investigate are caused by a misbehaving DNS server somewhere rather than a UTM problem.
localzuk Posted October 15, 2015 Posted October 15, 2015 I think they are referring to devices that use dedicated processors/ASIC processors to process the traffic, thereby reducing the latency involved. That said, it would surely come down to processing capability of the device? The difference should be in ms, which for most "cloud" software is simply not going to be noticed too much. It'd only really be an issue with realtime stuff.
SchoolsBroadband Posted October 15, 2015 Posted October 15, 2015 you have to look at the tech specs very carefully and ideally test the boxes with the same amount of traffic with different UTM functionality turned on. My view is the specs are about as useful as the results from emissions test on cars! Test, test and test again. Anyone saying you can do proper full inspection of traffic doing inline anti-virus scanning at full gig wirespeed on x86 boxes are either a) lying or b) not doing proper in-line anti-virus / UTM which in my opinion all schools and businesses should be using. Then try turn on layer 7 app control and other functionality too. As per @localzuk devices using ASIC processors have an advantage to x86 boxes as they offload specific functions to chipsets which are specifically designed to do them so you can get more throughput. This also leads to great scalability. What are all those customers going to do with their firewalls which are on the end of an 80Mbit FTTC connection when g.fast comes along initially starting at 300Mbit? For the vast majority of firewall vendors if you want to do full UTM then they'll have to go in the bin and you'll have to buy new firewalls. It's one of the reasons why we use carrier class virtual firewalls in the cloud as they can do gigs and gigs of traffic with full UTM turned on so you won't need to buy new firewalls in the future. Make sense? Thanks Dave
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now