Forum Discussion
Nik
Cirrus
Jun 14, 2010access restriction - pf vs irule?
we'll be making the transition from a pair of 6800s to a new viprion chassis in a few weeks. the current pair pushes about 900mb/s externally with 5k new connections per second.
about a year ago with v9.x we were using the built-in packet filter for simple access control but as traffic increased so did our cpu load.. when it hit the roof we disabled the packet filter and switched to simple irules that use data groups to either reject or allow every new connection on a per-vip basis.
we're now on v10 and soon moving to the viprions. Before i start any testing of my own i'm wondering what everyone's recent experiences are with packet filter performance? is it worth it to use pf over irules?
thanks!
- Hamish
Cirrocumulus
That's an interesting question... I haven't had to do packet filters for a long time on F5's (Since 9.1 IIRC). - Nom_55811
Nimbostratus
We're having some performance issue with packet filters too. Our current understanding is that packet filters are constrained to 20% of the available CPU power in the box, so you're somewhat likely to encounter issues when using it with any kind of substantial throughput. - Hamish
Cirrocumulus
Mmm.... I'd always sandwich external facing BigIP's with firewalls anyway. Because (As Support have told me in the past), they're not intended to be a security device... It's too easy to allow unintended access through an F5. Separating your security to a dedicated firewall and ensuring that the BigIP is there for content delivery is both more secure, and going to provide better performance as each device is optimised for the function they're performing. - Nik
Cirrus
just in case anyone was wondering what i found.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects