Firewall Wizards mailing list archives

Re: Firewall Utilization


From: Paul Robertson <proberts () patriot net>
Date: Tue, 15 Oct 2002 16:02:01 -0400 (EDT)

On Tue, 15 Oct 2002, Joe Keegan wrote:

I was curious if anyone would be willing to share the average
utilization (CPU/Mem) of their firewalls and the average amount of
traffic they deal with.

After working with a few different companies firewalls, I have found
that most are under utilized and often less expensive models could of
sufficed. If you are not willing to share your utilization details,
could you comment on your general experience with firewall utilization.

Be careful in thinking that average utilization is the metric it should 
be- like most communication services, planning for peak utilization is 
probably more attractive than for average given that CPU and memory are 
very inexpensive and in-place upgrading tends to be more expensive (in 
both downtime and support costs) than the upgrade premium.  Unplanned 
outages are probably more costly to most businesses than extra capacity.

Rarely are CPU and memory issues however, it's usually more about 
throughput.

I used to spec my firewalls to be able to handle full business load for 3 
years, with unprecedented staff increases and unknown protocol extension- 
the delta for the hardware on high-end equipment was ~$15,000- roughly 
$5k/year, under $2/user/year for interactive users, and pennies a year for 
mail users (~2.5-3k interactive users, >30,000 mail users.)  The ability 
to handle mailbombs in real-time and not have any issues at all from a 
usability/legitimate delivery standpoint was worth *way* more than $15,000 
per *incident*.

IOW: My experience is that getting lots of CPU and memory up front 
resulted in having hardware that usually sat idle, but was invaluable, and 
worth more than the delta between it and something that was closer to 
capacity full-time during the times when I had to deal with either a new 
request for something or an incident.  I'd get machines with a lot of 
extra interfaces, and not have to do significant capacity 
management/planning or downtime to spin up new networks or services.  
Specifying systems closer to the capacity wire usually meant spending 
about 1.5-2.5x as much in the long-run dealing with one-off requests, 
emergencies and new ventures.

If you want to spend time doing capacity planning, you can run things much 
closer to the line, but you're really not going to save a great deal of 
money (and if a firewall is a capital project rather than an expense 
it's probably more beneficial to the business- sometimes that affects how 
much you spend- $35,000 of assett(s) amortized over 3 or 5 years sometimes 
helps the balance sheets a lot more than $15,000 of up-front expense, then 
$5,000 of addtional immediate expense at year two for instance.)

Take into account the fact that I absolutely hate "systems management" 
stuff- I'd much rather spend my time building the next interesting thing 
than "managing" the current one- if $15,000 means "no SNMP/management 
station," it's a bargain in my mind.

Paul
-----------------------------------------------------------------------------
Paul D. Robertson      "My statements in this message are personal opinions
proberts () patriot net      which may have no basis whatsoever in fact."
probertson () trusecure com Director of Risk Assessment TruSecure Corporation

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: