Go Back   Technibble Forums > Technical Discussions > Networking

  Technibble Sponsor

Reply
 
Thread Tools Display Modes
  #1  
Old 05-10-2012, 07:30 PM
trendless trendless is offline
 
Join Date: Mar 2011
Location: Northeast BC, Canada
Posts: 97
trendless is an unknown quantity at this point
Default Virtualized gateways in production environment

Just read on Untangle's website that they don't recommend virtualization due to performance issues -- their wording makes it sound like a gateway/firewall issue, not Untangle-specific. That's the first I've heard of a gateway/firewall vendor say this... I know you've all got opinions, so let's hear 'em.
Reply With Quote
  #2  
Old 05-10-2012, 08:29 PM
angry_geek's Avatar
angry_geek angry_geek is online now
 
Join Date: Apr 2009
Location: herrin, il
Posts: 2,274
angry_geek has a spectacular aura aboutangry_geek has a spectacular aura about
Send a message via MSN to angry_geek
Default

I haven't been willing to run a gateway/firewall virtualized in production yet. I still like having that dedicated piece of hardware there. I have set up vpn managers virtually sitting behind the firewall. That has worked well.
__________________
Loring Preston
The Computer Doctor
Email Me

Reply With Quote
  #3  
Old 05-11-2012, 12:04 PM
YeOldeStonecat's Avatar
YeOldeStonecat YeOldeStonecat is offline
 
Join Date: Nov 2011
Location: Southeast Connecticut
Posts: 4,508
YeOldeStonecat is just really niceYeOldeStonecat is just really niceYeOldeStonecat is just really niceYeOldeStonecat is just really niceYeOldeStonecat is just really nice
Default

We are an Untangle partner.......my colleague has put Untangle in VMWare at some of his clients.....I've run Untangle in ESXi at my home (was in a dual core Atom with 2 gigs of RAM...it ran fine for home use).

Untangle is a layer 7 firewall. It puts quite a load on the hardware...likes direct connections to very strong NICs...Intel Pro, Broadcom...server grade hardware controller based NICs. It does not do well with "software" NICs.

If you're just doing basic filtering of web traffic, anti malware, reporting, some content filtering..it'll be fine. If you're doing heavier spam filtering, heavier QoS/traffic shaping...it will not do as well virtualized as it would on a bare metal install.

Security wise....like the Angry one above...I'm also a fan of having my firewalls be on dedicated, separate hardware. There is something inside of me that is wary of vulnerabilities in the virtualized environments...that something can come in one door..and spread to other guests. There have been exploits in VMware...I'm sure there will be more. So I prefer one piece of hardware at the edge...for the firewall...2 or more NICs....red NIC on the WAN...green NIC(s) going to the LAN...to a switch...and from there have your servers in whatever setup you want.
__________________
Resident "Geek on a Harley" doing IT in Southeast Connecticut
http://www.dynamic-alliance.com/
https://www.facebook.com/YeOldeStonecat
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 07:32 AM.


Powered by vBulletin®
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Technibble.com is based out of MELBOURNE, AUSTRALIA.