• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Bandwith in isp need help about hardware detail

Scheduled Pinned Locked Moved General pfSense Questions
12 Posts 4 Posters 3.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    s_265_925
    last edited by Jun 14, 2012, 10:05 AM

    hi all!
    i have an isp and i only need restriction for my users in some services and filter some ports …
    i have about 10 Gb in and 10 Gb out traffic!
    what hardwares should i use for best performance for this amount of traffic?
    what is your idea ?

    1 Reply Last reply Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Jun 14, 2012, 10:24 AM

      10Gigabits per second in and out?  :o

      I'm not sure there is any hardware that can do that in a single box. Due to the way pfSense works and the current performance of CPUs I believe the best possible throughput is 4-5Gbps. I could be wrong though.

      Following this thread with interest.

      Steve

      1 Reply Last reply Reply Quote 0
      • A
        allpoints
        last edited by Jun 14, 2012, 6:52 PM

        BIG Linux core switches:

        http://www.aristanetworks.com/

        ;D

        1 Reply Last reply Reply Quote 0
        • S
          s_265_925
          last edited by Jun 15, 2012, 7:27 AM Jun 15, 2012, 7:23 AM

          thanks all for replay  :) ! but i need cpu -ram- lan details ! can i use a multiprocessor server ;D?!  i need solution !! any idea ?
          before that ! is it possible to do this with this amount of traffic  ??? ???

          1 Reply Last reply Reply Quote 0
          • S
            stephenw10 Netgate Administrator
            last edited by Jun 15, 2012, 10:18 AM

            It hadn't even occurred to me that you might not be asking about pfSense.  ::)

            You probably could do this with pfSense but not with one machine. You would need to split your 10Gb connection across a number of boxes, say five each firewalling 2Gb.

            This is way out of my league to be honest. If you're serious about doing this I'm sure BSD perimeter could sort you out.

            Steve

            1 Reply Last reply Reply Quote 0
            • S
              s_265_925
              last edited by Jun 15, 2012, 1:09 PM Jun 15, 2012, 1:07 PM

              first thanks for helping!
              i think you are right splitting is the best way  ;D! now with your experience what do you think for 2 Gb traffic in and out what should i use ! i mean what hardwares can do that for me without hanging and other problems  ::).

              1 Reply Last reply Reply Quote 0
              • D
                dhatz
                last edited by Jun 15, 2012, 3:04 PM

                @stephenw10:

                10Gigabits per second in and out?  :o
                I'm not sure there is any hardware that can do that in a single box. Due to the way pfSense works and the current performance of CPUs I believe the best possible throughput is 4-5Gbps. I could be wrong though.

                Following this thread with interest.

                There was a topic on this sub-forum How Far Have You Scaled Your PFS Box?, but most posts are from the 2008/2009 era. It'd be interesting to hear about recent pfSense deployments, considering that newer FreeBSD supports several 10G cards.

                Based on what I read here http://lists.freebsd.org/pipermail/freebsd-pf/2012-June/006643.html there is also some effort underway to create an SMP-friendly version of PF for FreeBSD

                1 Reply Last reply Reply Quote 0
                • S
                  stephenw10 Netgate Administrator
                  last edited by Jun 15, 2012, 3:27 PM Jun 15, 2012, 3:19 PM

                  Ah, interesting reading. Interesting that this is a FreeBSD effort and not OpenBSD.
                  Also particularly happy to see that this is very much current.

                  SMP to one side it should be possible to beat the old records with modern hardware. What do you think is now possible?

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • S
                    s_265_925
                    last edited by Jun 16, 2012, 8:34 AM

                    SO WHAT ?  ::)  POSSIBLE OR NOT ?  ;D

                    1 Reply Last reply Reply Quote 0
                    • S
                      s_265_925
                      last edited by Jun 16, 2012, 10:23 AM

                      what do you think about this ?!
                      http://www.applianceshop.eu/index.php/firewalls/opnsense/opnsense-furious-hd-rack-edition-19-pfsense-appliance.html

                      1 Reply Last reply Reply Quote 0
                      • S
                        stephenw10 Netgate Administrator
                        last edited by Jun 16, 2012, 10:30 AM Jun 16, 2012, 10:25 AM

                        It is possible, yes.  ;)

                        I've never tested anything at these speeds personally so I can't give you any recommendations. As we discussed the currect, and likely near future, versions of pfSense are restricted by the fact that pf(4) does not multithread. Therefore to get the greatest throughput you need a machine with a high cpu clock speed per core rather than multiple cores at a lower speed. There is very little point in using a 16core xeon server for example.

                        Steve

                        Edit: The applianceshop hardware looks nice and you are guaranteed that it will all work with pfSense.  ;) Perhaps drop them a line and ask about maximum throughput.

                        Edit: They state 9.5Gbps in the brochure. But is that for a single connection or the total of many connections?

                        1 Reply Last reply Reply Quote 0
                        • S
                          s_265_925
                          last edited by Jun 18, 2012, 5:38 PM

                          thanks for helping  ;D

                          1 Reply Last reply Reply Quote 0
                          8 out of 12
                          • First post
                            8/12
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            This community forum collects and processes your personal information.
                            consent.not_received