Page 1 of 1

1100AH forward rule capacity

Posted: Wed Oct 08, 2014 3:36 am
by givemesam
Am i right to assume that the 1100AH (notx2) does not have the juice to filter 250mbps/20mbps on the forward chain for lets say about 30 virus ports and accept new/est/related and drop the rest?

I applied the port block on the forward chain and saw what i thought was drops from about 200mbps to less than 120, where the proc never really passed 40-50%. I feel like at 40-50% proc it is slowing down and should be treated like it is effecting performance.

BUT i could be wrong, as when i was trying to figure out what it was, enabling and disabling rules while watching its effects on resources/throughput (which can vary without much sense, i know) i had a simple queue set to 235mbps which was in yellow state, although i was not near it, i was around 130 at the time. I dropped the forward rules and the quoue for now.

Can i get someone who has used this router (NOT THE X2) with similar load and filters to comment?

thanks

Re: 1100AH forward rule capacity

Posted: Wed Oct 08, 2014 8:40 am
by jarda
Wrong approach to building a firewall. Use few accepting rules and general drop at the end of each chain instead dozens of individual drops and general accept at the end.