Jump to content

Recommended Posts

Posted

Hi all,

 

I was wondering if anyone here has a S15 appliance with a 10Gbps Leased Line connection?

 

We recently moved to 10Gbps on the understanding that the firewall was capable of near these speeds, but have subsequently been told that above 3-4Gbps is unlikely as the appliance cannot provide the throughput for more.

 

So, does anyone have any experience of this please?

 

Thank you.

Posted

Generally most the firewalls change the throughput depending on what you're doing with it. Obviously it's a very different scenario if you're only doing firewall vs ips/threat detection/decryption etc.

 

For example (With a Sophos XGS):

Firewall.png

 

Was there a specific type of throughput you're referring to in regards to the S15? As obviously the 10Gbps comment could be two different numbers referenced if you're referring to firewall only, and they're referring to threat protection etc

 

Steve

  • Thanks 1
Posted

Hi Steve,

 

Thanks for your reply.

 

Apologies, you are correct, I should have been more specific.

 

This is running only the Guardian module:

 

https://help.smoothwall.net/FilterFirewall/Content/7Guardian/Guardian.htm

 

Of these, we don't even run all of them. For example, we have disabled HTTPS inspection, so only basic traffic is monitored.

 

We don't run any VPN's, Proxy's or SMTP services as these are handled elsewhere.

 

Based on our usage, we were told before purchase that we should expect between 7-8Gbps, whereas, as I said previously, we are getting much less than that in practice.

 

I suspect this is going to be the maximum we are going to be able to achieve from our appliance, but I was wondering if anyone had had any direct experience for comparison sake.

Posted

Having ran Smoothies for years with dual 1Gb connections with no performance issues and now 10Gb becoming within reach i'm contemplating the upgrade. I'm also running s15's.

 

When appliance manufacturers actually publish their theoretical max performance, they'll give different figures for what you're trying to do. UTM/Firewall/VPN/AV/IPS/HTTPS inspection

 

Look at the watchguard M690 and the Fortigate 400F, they publish their theoretical max speeds and they vary wildly. Some pretty intense firewalls there but still lack the feature same feature set that Smoothwall offers.

 

Assuming you've got your Smoothwall connected directly to your core at 10gb, are you able to actually connect a computer capable of saturating your 10gb link directly to your core when nobody else is using the network and do some testing?

  • Thanks 1
Posted (edited)

We have two supermicro s14s that have had some custom work to get them to 10Gbps capable. our broadband is 10Gbps link but 2Gbps to the web, so I have only been able to test 10Gbps using iperf over our MPLS and it did get very close to that, but obviously this will just be the “firewall element” with no ips enabled.

 

It manages 2Gbps fine through filtering with https inspection etc

Edited by CrootUK
  • Thanks 2
Posted
Assuming you've got your Smoothwall connected directly to your core at 10gb, are you able to actually connect a computer capable of saturating your 10gb link directly to your core when nobody else is using the network and do some testing?

 

Yep, Smoothwall direct via SFP+ fibre connection at 10Gbps. We also got a SFP+ network card for a PC, so we connected it directly to the Smoothwall LAN interface, and managed the 3-4Gbps mentioned previously. This was a iperf test to a JISC test server. We also tried it via the core and got the same. Connecting directly to the router got us 10Gbps, hence we knew the bottleneck was somewhere inside our network.

 

Thanks,

Posted

From our experience firewall vendors publish the theoretical max if the wind blows in the right direction. If you truly want to know what you can get out of a firewall you need to test with the config you're going to use in a dev environment. I appreciate this is very difficult for a school to do and also to mimic the real world throughput of a school.

 

We travel to France to Fortinets testing labs where they a number of Ixia boxes which can mimic specific throughput scenario's. Very useful when you're paying £250k for a firewall and you want to know exactly what it can and can't do. See https://www.keysight.com/us/en/products/network-test/performance-monitoring.html

 

Fortinet also have a device called FortiTester which is pretty cool. Fortinet publish their throughputs on https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/Fortinet_Product_Matrix.pdf

 

To maximise the use of what you've got you may want to trust certain traffic policies and reduce what protection you use . Ultimately its down to budget but i do understand why a lot of vendors will struggle with 10Gbps services. This is going to be more commonplace as time goes on, particulary with the advent of XGS-PON FTTP services which are very cost effective. Firewall vendors will catch up as new chipsets become available with power processing power. The new G series chipset FortiGate have just released is pretty damn good, particulary for IPSEC VPN which I believe is the transport layer it uses for SD-WAN. As Fortinet develop and create their own ASIC chipsets this is generally where they have an advantage over other firewall vendors when you want to go very fast compared to vendors that generally use CPU's that go into normal computers.

 

Dave

  • Thanks 2
  • 1 month later...
Posted
Just an FYI you have to enable HTTP inspection to be compliant with safeguarding and KCSIE . Just because an appliance has a 10gbps port doesn't mean it can deliver 10gbps throughput. It's a Barn door on a bike shed analogy. From what I am aware Smoothwall do not have a firewall with a 10gbps throughput capability I believe, secondly if you are an average sized school I don't believe you are going to get close to a traffic throughput of 10gbs anytime in the next 8-10years. Working with sizing firewalls for the average 1/ 1.5k user school I have seen a peak throughput in a day at any given time of around 0.8-1.2gbps. An S15 from testing with SSL enabled can not handle 10gbps nor can an s14. Data sheets can be misleading and none provide number with SSL enabled because this is a how longs a piece of string question and most have dropped the URL filtering from their threat mix of data as this has a heavy impact on the performance numbers these are the things to look out for when checking those numbers on a datasheet.
  • Thanks 1
Posted

If you can update to our latest software version (Maiden) we have had customers experience much higher throughput.

Firewall performance testing is a dark art - particularly at higher speeds!

Posted
If you can update to our latest software version (Maiden) we have had customers experience much higher throughput.

Firewall performance testing is a dark art - particularly at higher speeds!

 

Hi Tom,

 

This has indeed been the case. Smoothwall have managed to work some magic as, with Maiden installed, we are now seeing 7Gbps throughput!

 

With these speeds, we are happy for now, so thanks to your developers for making this possible.

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...