Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Performance question

    Scheduled Pinned Locked Moved NAT
    5 Posts 3 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      MadX
      last edited by

      Hello,

      For a corporate network in co-location, i'll setup a Psense box (Xeon 2.6Ghz + 3 intel Nic).
      The bandwith will be around 50Mb/s, 32 publics IP and we will have 3 web servers under high traffic (500 000 connections/server per day) and 2 Mails servers, 2 Database servers.
      In term of performance is it better to use NAT 1:1 with virtual IPs or simply use a Port fowarding ?
      Thanks

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        You'll need virtual IPs for this, no matter if using portforwards or 1:1. Depending if you need lots of ports or just single ports (like a webserver) I would use portforwards for this rather than 1:1. Btwm with that box on a 50 mbit/s link you shouldn't have performance issues anyway.

        1 Reply Last reply Reply Quote 0
        • M
          MadX
          last edited by

          I will only need few ports (Web & Mail, remote administration, ssh, ftp).
          I will bridge one Nic for a pool of web servers with public IPs and one the other Nic i'll use a simple port fowarding for some services.

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            If you have as many or more public IP's as internal servers, I would suggest using only 1:1 for ease of setup and administration. It's much easier to deal with a firewall where X public IP maps to Y private IP, vs. X public IP port A maps to Y private IP port B, X public IP port C maps to Z private IP port D, etc. etc. With 32 public IP's that could get out of hand quickly.

            1 Reply Last reply Reply Quote 0
            • H
              hoba
              last edited by

              Btw, portforwards work with natreflection, 1:1 nat not, only in case you need that feature.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.