Deb Shinder Blog RSS

All Blogs  »  Deb Shinder Blog  »  ISA Central  »  Blog article: ISA Firewall VPN Throughput Nears 150Mbps

ISA Firewall VPN Throughput Nears 150Mbps

The “hardware” firewall vendors are beginning to feel the heat! I’ve heard from an increasing number of ISA firewall admins who are being approached by “hardware” firewall sales guys and being subjected to absurd fictional accounts of the ISA firewall’s capabilities and feature sets. The latest salvo of FUD shots has centered around the VPN space.

This got me thinking about what the ISA firewall offers in terms of VPN performance. I’ve been aware for some time that “hardware” firewall vendors have claimed to support almost 100Mbps VPN throughput on their ultra-costly VPN boxes. I’ve heard quotes that the ISA firewall supported “around” 20Mbps. This major disconnect between “hardware” VPN servers and the ISA firewall’s VPN service and gateway didn’t make a whole lot of sense. But I’ve always had other things to do and no one was pressing me for real numbers, so I didn’t try to reconcile the inconsistencies between the ISA firewall’s VPN and “hardware” VPN servers.

Now that the “hardware” VPN and packet filtering guys feel the ISA firewall heat and have started to launch their sales campaigns against the ISA firewall , I decided to check out what the real performance numbers are for the ISA firewall compared to the old school “hardware” guys.

OK, get this. If we mirror an ISA firewall VPN configuration so that its similar to what you see in a typical “hardware” stateful packet inspection firewall doing double duty as a VPN server, here’s what you see:

ISA Firewall Remote Access VPN throughput = 76Mbps

ISA Firewall Site to Site VPN throughput = 162Mbps

(Source Best Practices for Performance in ISA Server 2004 at http://www.microsoft.com/technet/prodtechnol/isa/2...s.mspx)

Hey “hardware” firewall guy, put those numbers in your pipe and smoke it!

img7

HTH,

Tom

Thomas W Shinder, M.D.

Site: www.isaserver.org

Blog: http://blogs.isaserver.org/shinder/

Book: http://tinyurl.com/3xqb7

MVP — ISA Firewalls

3 Responses to “ISA Firewall VPN Throughput Nears 150Mbps”

  1. Jeff Douglass Says:

    April 6th, 2006 at 3:40 pm

    Can you expand a bit on this regarding the HW configuration you did your test on along with the type of traffic ( small packet vs Large packet) used.

    Thanks

    Jeff

  2. Thomas Shinder Says:

    April 6th, 2006 at 5:44 pm

    Hi Jeff,
    I didn’t do the testing. Check out the link for the ISA firewall best practices white paper.
    HTH,
    Tom

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Follow TechGenix on Twitter