This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Circumventing processor throughput limitation on UTM using DMZ?

I have a home office with a SG-105.  After recently upgrading to a 1Gbps broadband circuit, I am trying to figure out how to use that bandwidth for my home purposes, without the limitations of the UTM.  

If I configure a port for a DMZ, can I shut off packet inspection for that port and then have access to the full internet bandwidth, understanding that I won't have security on that port?  Or will the throughput limitation of this sized UTM still apply?

Thanks for any input on this subject.

Steve



This thread was automatically locked due to age.
Parents
  • Hi Steve,

    The SG105 is by and far not suitable for a gigabit connection, let alone for just iptables.

    Just for perspective, Sophos official recommendation is an SG430 for a gigabit internet connection with IPS enabled, you could maybe get away with an SG330 for just AV.

    The processor of an SG430 rev. 2 is an e3-1225v3 (iirc) and the sg105 is a dual core atom or a celery stick if i remember correctly.

    Unfortunately, you can only either turn off IPS for your DMZ for iptables security only or you will have to upgrade (considerably).

    Sorry for the bad news.

    Emile

Reply
  • Hi Steve,

    The SG105 is by and far not suitable for a gigabit connection, let alone for just iptables.

    Just for perspective, Sophos official recommendation is an SG430 for a gigabit internet connection with IPS enabled, you could maybe get away with an SG330 for just AV.

    The processor of an SG430 rev. 2 is an e3-1225v3 (iirc) and the sg105 is a dual core atom or a celery stick if i remember correctly.

    Unfortunately, you can only either turn off IPS for your DMZ for iptables security only or you will have to upgrade (considerably).

    Sorry for the bad news.

    Emile

Children