Sorry to bring back a zombie thread, but it seems very relevant. I recently got gigabit to the home, what specs now would suffice to get IPS to those speeds of possible? I have a g3258 with 16gb available @ 4.5ghz.
Right now the NSA2400 is capping out at 200/200. I'm vetting solutions and since we are a Sophos partner I figure why not try The home version?
Hi, Tuan, and welcome to the UTM Community!
I also saw your conversation with Jason Lenn in another thread. The most I've heard of anyone getting with Snort active is a little over 300Mbps per user. We discussed using ESXi and "stacking" processors to get what Snort might see as a single 8GHz processor. One of the participants said it couldn't be done, but several others thought it could be - I have no idea! If you know enough to try that, please let us know if it works.
Cheers- Bob
Hi, Tuan, and welcome to the UTM Community!
I also saw your conversation with Jason Lenn in another thread. The most I've heard of anyone getting with Snort active is a little over 300Mbps per user. We discussed using ESXi and "stacking" processors to get what Snort might see as a single 8GHz processor. One of the participants said it couldn't be done, but several others thought it could be - I have no idea! If you know enough to try that, please let us know if it works.
Cheers- Bob
I most definitely am familiar with that type of setup. I'm pretty sure the pool does not aggregate the CPU speed between cores in a hypervisor such as ESXi. That'd be cool for things like SQL, but it doesn't really work that way from what I've seen.
I just sold off the ESXi box last week and am looking for a replacement. We'll see.
Now, what does the XG firewall use in place of Snort? I understand it doesn't have the limitations of SG/UTM.
While I want a single user gig throughput, I'm okay with multiple users getting full bandwidth as a total if that's the most probable option. Is it really done per user, or per data stream? For example if I'm torrenting, would it use multiple threads and give a single PC full throughput?