From owner-freebsd-isp@FreeBSD.ORG Mon Apr 12 07:18:52 2004 Return-Path: Delivered-To: freebsd-isp@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id AD6E016A4CE for ; Mon, 12 Apr 2004 07:18:52 -0700 (PDT) Received: from mail.wintek.com (mail.wintek.com [199.233.104.76]) by mx1.FreeBSD.org (Postfix) with ESMTP id 5926643D4C for ; Mon, 12 Apr 2004 07:18:52 -0700 (PDT) (envelope-from rjk@wintek.com) Received: from wintek.com (rjk.wintek.com [206.230.2.248]) (authenticated bits=0)i3CEIi2i077562 for ; Mon, 12 Apr 2004 09:18:44 -0500 (EST) (envelope-from rjk@wintek.com) Message-ID: <407AA4C5.50405@wintek.com> Date: Mon, 12 Apr 2004 09:16:37 -0500 From: Richard J Kuhns Organization: Wintek Corporation User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.6) Gecko/20040113 X-Accept-Language: en-us, en MIME-Version: 1.0 To: freebsd-isp@freebsd.org Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Scanned: by amavisd-new X-Spam-Status: No, hits=-0.1 required=7.0 tests=USER_AGENT_MOZILLA_UA,X_ACCEPT_LANG version=2.55 X-Spam-Checker-Version: SpamAssassin 2.55 (1.174.2.19-2003-05-19-exp) Subject: NAT and traffic shaping X-BeenThere: freebsd-isp@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Internet Services Providers List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 12 Apr 2004 14:18:52 -0000 We have a customer (an apartment complex) who wants us to deploy a FreeBSD box that will handle NAT for 400 to 600 machines (so figure multiple connections per machine) and that can handle a steady 12 to 15 Mb of ethernet traffic, both directions. I'm sure we'll also want to do some traffic shaping. Would anyone care to offer suggestions/recommendations/horror stories about implementing this? Specifically, how hefty a box should we use (RAM/CPU), and which version of FreeBSD? We're mostly running 4.9-stable right now and it's been very reliable. I've installed 5.2.1 on a couple of boxes with no major problems, but they also haven't been heavily loaded. Any comments or suggestions would be greatly appreciated. - Rich -- Richard Kuhns Wintek Corporation E-mail: rjk@wintek.com 427 N 6th Street Tel: +1 (765) 742-8428 Lafayette, IN 47901-1126 Fax: +1 (765) 742-0646 United States of America