[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

question about PF performance



Hello,
I have to build a firewall machine for a university campus.
The firewall will be installed behind the core gigabit switch
which is a Extreeme Black Diamond, and it will be in bridging mode.
Don't ask me why I don't use the black diamond... I will use OpenBSD
because of political reaons about the Network campus management that
is beyond the topic of my question now.
Anyway I will have this OpenBSD box ( I Was thinking about a 3GHz P4 dell
power edge), with 2 gigabit interfaces.
The maximum speed will be 1Gbit/sec.
What I Want to ask you is if in your opinion OpenBSD can support such
a peak traffic of 1Gbit/s in bridging mode between its two interfaces
filtering the traffic ?
Then a second question.
With PF I Can filter up to OSI level 4, and I plan to do bandwith
management also. If I want to filter up to level OSI 7, is there any
particular application I can use to do that ?
I know it's very CPU intensive to filter at application level, but if I
need to do it sometimes, is there any way to do it on OpenBSD?

thanks very much

Rick