QMC_IT Posted March 8, 2024 Posted March 8, 2024 Hi all, I was wondering if anyone here has a S15 appliance with a 10Gbps Leased Line connection? We recently moved to 10Gbps on the understanding that the firewall was capable of near these speeds, but have subsequently been told that above 3-4Gbps is unlikely as the appliance cannot provide the throughput for more. So, does anyone have any experience of this please? Thank you.
Steve21 Posted March 8, 2024 Posted March 8, 2024 Generally most the firewalls change the throughput depending on what you're doing with it. Obviously it's a very different scenario if you're only doing firewall vs ips/threat detection/decryption etc. For example (With a Sophos XGS): Was there a specific type of throughput you're referring to in regards to the S15? As obviously the 10Gbps comment could be two different numbers referenced if you're referring to firewall only, and they're referring to threat protection etc Steve 1
QMC_IT Posted March 8, 2024 Author Posted March 8, 2024 Hi Steve, Thanks for your reply. Apologies, you are correct, I should have been more specific. This is running only the Guardian module: https://help.smoothwall.net/FilterFirewall/Content/7Guardian/Guardian.htm Of these, we don't even run all of them. For example, we have disabled HTTPS inspection, so only basic traffic is monitored. We don't run any VPN's, Proxy's or SMTP services as these are handled elsewhere. Based on our usage, we were told before purchase that we should expect between 7-8Gbps, whereas, as I said previously, we are getting much less than that in practice. I suspect this is going to be the maximum we are going to be able to achieve from our appliance, but I was wondering if anyone had had any direct experience for comparison sake.
slugshead Posted March 9, 2024 Posted March 9, 2024 Having ran Smoothies for years with dual 1Gb connections with no performance issues and now 10Gb becoming within reach i'm contemplating the upgrade. I'm also running s15's. When appliance manufacturers actually publish their theoretical max performance, they'll give different figures for what you're trying to do. UTM/Firewall/VPN/AV/IPS/HTTPS inspection Look at the watchguard M690 and the Fortigate 400F, they publish their theoretical max speeds and they vary wildly. Some pretty intense firewalls there but still lack the feature same feature set that Smoothwall offers. Assuming you've got your Smoothwall connected directly to your core at 10gb, are you able to actually connect a computer capable of saturating your 10gb link directly to your core when nobody else is using the network and do some testing? 1
CrootUK Posted March 10, 2024 Posted March 10, 2024 (edited) We have two supermicro s14s that have had some custom work to get them to 10Gbps capable. our broadband is 10Gbps link but 2Gbps to the web, so I have only been able to test 10Gbps using iperf over our MPLS and it did get very close to that, but obviously this will just be the “firewall element” with no ips enabled. It manages 2Gbps fine through filtering with https inspection etc Edited March 10, 2024 by CrootUK 2
QMC_IT Posted March 11, 2024 Author Posted March 11, 2024 Assuming you've got your Smoothwall connected directly to your core at 10gb, are you able to actually connect a computer capable of saturating your 10gb link directly to your core when nobody else is using the network and do some testing? Yep, Smoothwall direct via SFP+ fibre connection at 10Gbps. We also got a SFP+ network card for a PC, so we connected it directly to the Smoothwall LAN interface, and managed the 3-4Gbps mentioned previously. This was a iperf test to a JISC test server. We also tried it via the core and got the same. Connecting directly to the router got us 10Gbps, hence we knew the bottleneck was somewhere inside our network. Thanks,
SchoolsBroadband Posted March 11, 2024 Posted March 11, 2024 From our experience firewall vendors publish the theoretical max if the wind blows in the right direction. If you truly want to know what you can get out of a firewall you need to test with the config you're going to use in a dev environment. I appreciate this is very difficult for a school to do and also to mimic the real world throughput of a school. We travel to France to Fortinets testing labs where they a number of Ixia boxes which can mimic specific throughput scenario's. Very useful when you're paying £250k for a firewall and you want to know exactly what it can and can't do. See https://www.keysight.com/us/en/products/network-test/performance-monitoring.html Fortinet also have a device called FortiTester which is pretty cool. Fortinet publish their throughputs on https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/Fortinet_Product_Matrix.pdf To maximise the use of what you've got you may want to trust certain traffic policies and reduce what protection you use . Ultimately its down to budget but i do understand why a lot of vendors will struggle with 10Gbps services. This is going to be more commonplace as time goes on, particulary with the advent of XGS-PON FTTP services which are very cost effective. Firewall vendors will catch up as new chipsets become available with power processing power. The new G series chipset FortiGate have just released is pretty damn good, particulary for IPSEC VPN which I believe is the transport layer it uses for SD-WAN. As Fortinet develop and create their own ASIC chipsets this is generally where they have an advantage over other firewall vendors when you want to go very fast compared to vendors that generally use CPU's that go into normal computers. Dave 2
KDW1987 Posted May 9, 2024 Posted May 9, 2024 Just an FYI you have to enable HTTP inspection to be compliant with safeguarding and KCSIE . Just because an appliance has a 10gbps port doesn't mean it can deliver 10gbps throughput. It's a Barn door on a bike shed analogy. From what I am aware Smoothwall do not have a firewall with a 10gbps throughput capability I believe, secondly if you are an average sized school I don't believe you are going to get close to a traffic throughput of 10gbs anytime in the next 8-10years. Working with sizing firewalls for the average 1/ 1.5k user school I have seen a peak throughput in a day at any given time of around 0.8-1.2gbps. An S15 from testing with SSL enabled can not handle 10gbps nor can an s14. Data sheets can be misleading and none provide number with SSL enabled because this is a how longs a piece of string question and most have dropped the URL filtering from their threat mix of data as this has a heavy impact on the performance numbers these are the things to look out for when checking those numbers on a datasheet. 1
tom_newton Posted May 13, 2024 Posted May 13, 2024 If you can update to our latest software version (Maiden) we have had customers experience much higher throughput. Firewall performance testing is a dark art - particularly at higher speeds!
QMC_IT Posted May 14, 2024 Author Posted May 14, 2024 If you can update to our latest software version (Maiden) we have had customers experience much higher throughput. Firewall performance testing is a dark art - particularly at higher speeds! Hi Tom, This has indeed been the case. Smoothwall have managed to work some magic as, with Maiden installed, we are now seeing 7Gbps throughput! With these speeds, we are happy for now, so thanks to your developers for making this possible. 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now