Firewall Wizards mailing list archives
Re: Firewall Utilization
From: Paul Robertson <proberts () patriot net>
Date: Tue, 15 Oct 2002 16:02:01 -0400 (EDT)
On Tue, 15 Oct 2002, Joe Keegan wrote:
I was curious if anyone would be willing to share the average utilization (CPU/Mem) of their firewalls and the average amount of traffic they deal with. After working with a few different companies firewalls, I have found that most are under utilized and often less expensive models could of sufficed. If you are not willing to share your utilization details, could you comment on your general experience with firewall utilization.
Be careful in thinking that average utilization is the metric it should be- like most communication services, planning for peak utilization is probably more attractive than for average given that CPU and memory are very inexpensive and in-place upgrading tends to be more expensive (in both downtime and support costs) than the upgrade premium. Unplanned outages are probably more costly to most businesses than extra capacity. Rarely are CPU and memory issues however, it's usually more about throughput. I used to spec my firewalls to be able to handle full business load for 3 years, with unprecedented staff increases and unknown protocol extension- the delta for the hardware on high-end equipment was ~$15,000- roughly $5k/year, under $2/user/year for interactive users, and pennies a year for mail users (~2.5-3k interactive users, >30,000 mail users.) The ability to handle mailbombs in real-time and not have any issues at all from a usability/legitimate delivery standpoint was worth *way* more than $15,000 per *incident*. IOW: My experience is that getting lots of CPU and memory up front resulted in having hardware that usually sat idle, but was invaluable, and worth more than the delta between it and something that was closer to capacity full-time during the times when I had to deal with either a new request for something or an incident. I'd get machines with a lot of extra interfaces, and not have to do significant capacity management/planning or downtime to spin up new networks or services. Specifying systems closer to the capacity wire usually meant spending about 1.5-2.5x as much in the long-run dealing with one-off requests, emergencies and new ventures. If you want to spend time doing capacity planning, you can run things much closer to the line, but you're really not going to save a great deal of money (and if a firewall is a capital project rather than an expense it's probably more beneficial to the business- sometimes that affects how much you spend- $35,000 of assett(s) amortized over 3 or 5 years sometimes helps the balance sheets a lot more than $15,000 of up-front expense, then $5,000 of addtional immediate expense at year two for instance.) Take into account the fact that I absolutely hate "systems management" stuff- I'd much rather spend my time building the next interesting thing than "managing" the current one- if $15,000 means "no SNMP/management station," it's a bargain in my mind. Paul ----------------------------------------------------------------------------- Paul D. Robertson "My statements in this message are personal opinions proberts () patriot net which may have no basis whatsoever in fact." probertson () trusecure com Director of Risk Assessment TruSecure Corporation _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Firewall Utilization Joe Keegan (Oct 15)
- Re: Firewall Utilization Paul Robertson (Oct 15)
- Re: Firewall Utilization black (Oct 15)
- <Possible follow-ups>
- RE: Firewall Utilization Noonan, Wesley (Oct 15)
- Re:Firewall Utilization Brian Ford (Oct 15)
- RE: Firewall Utilization Zill, Greg (Oct 16)
- Re: RE: Firewall Utilization Achim Dreyer (Oct 16)
- Re: RE: Firewall Utilization Balazs Scheidler (Oct 16)
- Re: RE: Firewall Utilization Achim Dreyer (Oct 16)
