True True.  But not many PFs do it well that are under a grand(ie, most low
end boxes experience incoming port nat speed decrease in
multi-port-nat-mode.)  Even the low,low end sub $1000 NS box keeps up at
wire speed and does intrusion detection and traffic shaping without
complaining.  But don't get me wrong.  We outgrew the lowend stuff a good
bit ago.  Infact we don't even use the NS boxes.  But for the sake of
argument, it is worth noting that the band\buck factor is high with the
lowend boxes as well as the big expensive ones.

A word of caution for those of you using the NS:  If you try to initiate a
port scan from your internal network to the internet or a VPN tunnel through
the NS, you will DOS the NS box if you are using anything but the new firm.
Also, if you are protecting an IIS server with an NS box and the IIS box
starts firing out code red packets, it will DOS your NS box by killing all
of its available connections.  Just a little something for your G-Wiz file.





-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Len Conrad
Sent: Thursday, March 07, 2002 2:44 PM
To: [EMAIL PROTECTED]
Subject: RE: [IMail Forum] Firewalls



>lotsa packet filter to the same.

lotsa packet filters do the same

(it's some disease coming on)


http://MenAndMice.com/DNS-training
http://BIND8NT.MEIway.com : ISC BIND for NT4 & W2K
http://IMGate.MEIway.com  : Build free, hi-perf, anti-abuse mail gateways


Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to