Hello all,
I am currently responsible for replacing an old DELL 2950 running IPF for a new server, as we are currently having some performance issues.
I want to use PF and the latest stable version of FreeBSD as it seems to me to be the best open source stateful firewall at the moment.
My main concern is that I need to be able to handle 150k concurrent connections + 5k new connections/sec + a throughput of 1.0~1.5Gb/s. The default configuration for PF is probably not well suited for such a large environment, so I need some help with some tuning guidance.
What variables should I consider (state tables, mbufs, etc) ? Is there any tuning guide for large scale routers/firewalls running PF?
I am currently responsible for replacing an old DELL 2950 running IPF for a new server, as we are currently having some performance issues.
I want to use PF and the latest stable version of FreeBSD as it seems to me to be the best open source stateful firewall at the moment.
My main concern is that I need to be able to handle 150k concurrent connections + 5k new connections/sec + a throughput of 1.0~1.5Gb/s. The default configuration for PF is probably not well suited for such a large environment, so I need some help with some tuning guidance.
What variables should I consider (state tables, mbufs, etc) ? Is there any tuning guide for large scale routers/firewalls running PF?