pfSense ȭ ó뷮  ֳ?

ȸK   
   ȸ 15605   õ 0    

장터발 솔리게이트에 pfSense를 설치했습니다.
 
전면에 10/100/1000 포트 6개중 5번포트(6번째)를 WAN으로 잡았고
확장슬롯에 10/100/1000 4포트가 있습니다 (10/100을 교체 예정)
 
솔리게이트 + pfSense로 얼마나 많은 트래픽의 처리가 가능한지 확인을 하고 싶은데 어떻게 해야 하나요?
 
5번 포트를 스위치에 연결하고,
전면부의 0-4번 은 서비스용 서버에 연결하고
후면부의 포트는 내부용 서버에 연결할 예정 입니다.
- to be continue -
ª ϼ ϰ.
2013-10
pfSense  ͸ Ѵٰ ɴϴ.
Reporting and Monitoring
RRD Graphs
The RRD graphs in pfSense maintain historical information on the following.

CPU utilization
Total throughput
Firewall states
Individual throughput for all interfaces
Packets per second rates for all interfaces
WAN interface gateway(s) ping response times
Traffic shaper queues on systems with traffic shaping enabled

Ѵ ׳ ýۿ ͸ Ͻð 쿡 snmp ̿ؼ
ټ ͸ Ͻø ˴ϴ.
     
ȸK 2013-10
Ʈ ó 뷮 estimate ִ ?
Ϲ pfSense ġϴ ó뷮 Ȯ ʿ
ã ֽϴ.
          
2013-10
ϴ iperf ̿ؼ Ŷloss ߻ϴ Ƴ ͽϴ. Ŷ ְ ִ  Ŭ̾Ʈ ִٸ ̷ ׽Ʈ غô° DZ ͽϴ.
pcټ---ȭ---ټ ̷ ϰ ټ iperf , pcټ iperf client
׽Ʈ ϸ Ŷ ȭ ļ Ŷ ν ߻ϴ ã մϴ. ȭ rrd graph ȮϽø 뷫 Ѱġ ͳ׿.
ȭ  Ǵ 𸣰
ⰡƮ Ʈѷ ޷ְ ޸ ϸ 700~800Mbps Ƽ ϴ.
               
ȸK 2013-10
޸𸮴 DDR2-6400U 2G̰
CPU ۵Ǿ ˰ ֽϴ (CPU ʾƼ...)
700-800 mbps ƿ ?

߰ 4G øٸ ˰ ͽϴ.
縸  Ǵµ,
ȭ Ẹ ʾƼ... ȵdz׿.
                    
2013-10
freebsd غ ʾƼ Ȯ 帮
ڸ ȭ κ iptables Ŷ Ʈ ϰ ˴ϴ.
iptables ϸ鼭 (conntrack) ⺻ ϰ Ǵµ ý ޸
ް ˴ϴ. óҼִ Ǽ Ѱ迡 ϰ Ǿ ÿ Ŀؼ ߻ϸ
̻ ó ϰ Ǵ 찡 ϴ.
޸𸮴 ˳ϰ ° ϴ.
⺻ 1G̻ ýۿ ip_conntrack_max 65536 Դϴ.
ظ ϴٸ ý ޸𸮿 ־
ø ϴ. ӿ Ȯ ʰ ޸𸮸 ּž մϴ.
Ŀι ý۸޸(byte)/16384 Ͻø ip_conntrack_max ´ٰ Ǿֽϴ.
                         
ȸK 2013-10
CentOS ͼ FreeBSD 𸨴ϴ.
1G 6400U 2 ִµ, ũ 2 2G ٲ 4G ɴϴ.
׷ 2G 6400U ̶ ϱ .

2G 12 ׿.
50mbps apache connection(apachectl status ̴ )
10-30 ϱ 500mbps ̻ ...
´°ɱ? ^^
ȸK 2013-10
https://doc.pfsense.org/index.php/Hardware_requirements#Hardware_Sizing
High Throughput Environments

In environments where extremely high throughput through several interfaces is required, especially with gigabit interfaces, PCI bus speed must be taken into account. When using multiple interfaces in the same system, the bandwidth of the PCI bus can easily become a bottleneck. Most typical motherboards only have one or two PCI buses, and each can run an absolute maximum of 133 MBps, or 1064 Mbps. That's less than one gigabit interface can transfer. PCI-X can transfer up to 1056 MBps, or about 8.25 Gbps.

PCIe (PCI Express) offer significantly higher bandwidth than traditional PCI and PCI-X slots. PCIe 1.0 offers a bandwidth of 250MB/sec per lane, while PCIe 2.0 doubles that to 500MB/sec per lane, while PCIe 3.0 offers a staggering 985MB/sec per lane although as of winter 2013 there are no PCI 3.0 NICs on the market. Most single and multi-port NICs (both integrated and add-on PCIe cards) are connected via an x4 (four lane PCIe) offering plenty bus headroom to saturate multiple gigabit links. Both single and dual port 10gbit adaptors are typically PCI-e x8.

If you need sustained gigabit throughput at wire speed, you will want a server-class motherboard with PCIe or PCI-X slots with matching PCIe/PCI-X NIC's. You'll also need a 2.8+ GHz CPU.
ȸK 2013-10
http://www.firewallhardware.it/en/pfsense_selection_and_sizing.html
201-500 Mbps No less than 1.0 GHz CPU Dual Core

A 266 MHz CPU will max out at around 4 Mbps of IPsec throughput, a 500 MHz CPU can push 10-15 Mbps of IPsec, and relatively new server hardware (Xeon 800 FSB and newer) deployments are pushing over 100 Mbps with plenty of capacity to spare.

ָƮ pfSense ø 500mbps ̻ ϴ.
ȸK 2013-10
http://pfsensesetup.com/pfsense-hardware-requirements/

ڷḦ Դϴ...
ǻڵ߿ atomε 200mbps óѴٰ ϴ Xeon 迭̸ 500mbps ϴ.
2013-10
2G 500Mbps ó մϴ.
񿡼 Ŀ Ƽ¡ ϹǷ ϴ ׽Ʈ غð Űø ǽǵ ϳ׿
iptables  conntrack  ȭ  Ǿ ִĿ 󼭵 ޽ϴ.
Ǵ Ʈ ؼ conntrack ʴ°͵ ߿ ϳԴϴ.
     
ȸK 2013-10
ũ CF 250G sata üߴµ, װ ?
ӵ ssd ٲٴ ?
          
2013-10
ipfw iptables Ŀο ϴ ༮̹Ƿ
ũ ӵ ǹ̰ ϴ.
ũ ϴ ⲯؾ rrdtool ̿ؼ ׷ αױҶ ϰ ɰ̴ϴ.
rrdtool ũ ٲ۴ٰ ص üҸŭ ū ̸ Դϴ.
               
ȸK 2013-10
մϴ. ӵ CF ū Ŷ ߽ϴ.
ebay ٺ, Ƽ4 50mbps ó ϳ׿.
pfSense ϴ.
     
ȸK 2013-10
netgear utm50 4 ó ѵ, 400mbps Դϴ.
2G 6 conntrack ϸ 600mbps Ѱ ƴұ?
1 conntrack = 1 session ´ 𸣰ڽϴ.

Users:    20-60
Throughput:    400mbps
Max. Sessions:    40,000
Lan Ports:    6
WAN Ports:    2
VPN Tunnels:    50


QnA
Page 3405/5725
2015-12   1771767   ް
2014-05   5246462   1
2020-06   3971  
2014-09   4152   ȯ
2023-06   1694  
2014-09   18068   I赿
2016-12   4790   refreshair
2020-06   3569  
2013-03   8185   ô
2013-03   5403   akfalles
2014-09   4870   츶ũ
2018-02   4490   ö
2023-06   3942   ȣڰ
2014-09   6598   ȫoo
2010-02   8099   stone92
2013-04   6003   HEUo
2016-01   5064   ȯ
2016-01   11098   ITES
2023-07   1935  
2021-12   2035   ູϼ
2016-01   6138   Ѽ
2020-07   5328