FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] Firewall bake-off?

To: "Firewall Wizards Security Mailing List" <firewall-wizards@listserv.icsalabs.com>
Subject: Re: [fw-wiz] Firewall bake-off?
From: "K K" <kkadow@gmail.com>
Date: Wed, 21 Mar 2007 16:45:52 -0500
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.icsalabs.com
In-reply-to: <90b025640703210959k245f42e7tcbf3a0cffaec6eae@mail.gmail.com>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <948caa7e0703121637sa283960n552ec4e14900666f@mail.gmail.com> <1CE69584EC644F40B2D9B69003C56AD91F9D025B1B@carbon.japrinting.com> <dc718edc0703181946r2052f437v5afe6d84fc8417f7@mail.gmail.com> <4600554A.9060403@gmail.com> <90b025640703210959k245f42e7tcbf3a0cffaec6eae@mail.gmail.com>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
On 3/21/07, Jim MacLeod <jmacleod@gmail.com> wrote:
> On 3/20/07, Zachary Grafton <chaotic.chowder@gmail.com> wrote:
> > Well, the greatest thing about the sidewinder is how easy it is to
> > configure things. It does have clustering and nice failover features,
> > which are in my opinion, extremely important. If you are worried about
> > performance with a Sidewinder, just buy another one and cluster them.
>
> Does it support active-active load splitting?  Or do you need an
> external load balancer for that?

The Sidewinder G2 does have active-active load-splitting, but many
customers (us included) choose to use an external load-balancer.

One reason we use an external load balancer appliance is because our
LB can do the one load-control approach missing from Sidewinder G2:
limit clients by bandwidth, session rate, and max simultaneous
sessions (Sidewinder has rate limiting only for IP-Filter, and no ToS
or bandwidth controls).


> How destructive is the transition when one fails?
> How extensive is the state sync?

Clusters share IP-filter state and configuration only, any proxied TCP
connections on the failed firewall will abend when a failover event
occurs.


> Will it scale to n+1, or is it limited to 2 firewalls?

The web site states you can have 5 firewalls in a cluster.  I believe
they're working towards highly scalable load-sharing, but I don't know
what the current load-sharing options are.

Kevin  "Just a (mostly) happy customer" Kadow
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>