From owner-freebsd-questions@FreeBSD.ORG Wed Feb 9 19:06:16 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3B67E16A4CE for ; Wed, 9 Feb 2005 19:06:16 +0000 (GMT) Received: from rwcrmhc11.comcast.net (rwcrmhc11.comcast.net [204.127.198.35]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1EF7043D1F for ; Wed, 9 Feb 2005 19:06:16 +0000 (GMT) (envelope-from mag@hamletinc.com) Received: from [192.168.12.99] (c-24-19-27-240.client.comcast.net[24.19.27.240]) by comcast.net (rwcrmhc11) with ESMTP id <2005020919061501300d48qke>; Wed, 9 Feb 2005 19:06:15 +0000 Message-ID: <420A5ECD.4090308@hamletinc.com> Date: Wed, 09 Feb 2005 11:04:45 -0800 From: "Mark A. Garcia" User-Agent: Mozilla Thunderbird 0.6 (X11/20040519) X-Accept-Language: en-us, en MIME-Version: 1.0 To: darryl@osborne-ind.com References: <000801c50ec5$a2115c00$0701a8c0@darryl> In-Reply-To: <000801c50ec5$a2115c00$0701a8c0@darryl> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit cc: freebsd-questions@freebsd.org Subject: Re: Firewall throughput question X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 09 Feb 2005 19:06:16 -0000 Darryl Hoar wrote: >Greetings, >I have had a Freebsd firewall (Older computer with (1) 3com 10Mb >ethernet PCI card, and (1) 3 com 10/100 Mb ethernet PCI card). >The firewall croaked on me (motherboard died). As a quick fix, >I plugged in a Linksys BEFSX41. > >My Question is, should I build a new Freebsd firewall or just >continue using the Linksys ? Throughput and security are my >concern. I can have up to 20 machines on the LAN at one time >using the internet, so traffic throughput is a factor. > >Anyway, my inclination is to build a new freebsd firewall, but >don't want to do the work if the Linksys is good enough. > >Thanks for any ideas or suggestions. > How old are those 3com cards? I think the most important area to look at is guaging how much packet loss will occur under these high loads. And that in-of-itself might appear differently in one type of traffic and not others, i.e. vpn, ssh, encrypted traffic, ssl. Also, how well and quick a device can handle packet loss can be determined by newer equipment (new linksys router) handling packets that come over the wire verses and older 3com card with aging firmware. It's a toss up that's hard to make a definative suggestion... unless you can do what Hexren mentioned and pit them against each other. That would be the easiest way to appease your needs. -.mag