I just upgraded both sides of my work-to-home network link to FIOS Gigabit. Previously had been 150/150 at home and 75/75 at work but now both will big FIOS Gig.
Was using Checkpoint 680 appliances with IPSEC/VPN. Did the job well. iperf3 testing across the link showed full 75 mbit speeds which was my slowest link.
I knew the checkpoints wouldn't keep up with the new speeds but I was surprised to see that they won't even keep up with WAN speeds either just as a firewall. Speed tests showing 450/450 and it's rated at 1.5gb firewall speed. Not using any of the "blades", just firewall.
Tested in my lab (not vpn, just straight firewall connections) and was only getting 500/500 with utilization pegged so these boxes just won't keep up. Again disapointing considering the specs say 1.5Gb/s. For kicks I replaced my test checkpoint box with a Verizon G1100 and did same test and was seeing 800-900 which is about all I figured I was going to get out of a gig connection.
So I've been researching new routers (don't need wifi, handled elsewhere) but they must have ipsec/vpn capability so I can connect both locations. My emphasis needs to be on ipsec/vpn throughput. I really want to saturate the link as much as possible and I understand that ipsec/vpn has all the added overhead of encryption.
One box that I'm going to look at is the ubiquiti ER-4 (or ER-4P as I'm seeing it called in the production release) which is due out this month. Say's it's 4 times faster than the ERPro-8 which is their previous model. I tried to get some VPN tests from the beta testers but nobody had done that testing.
Looking for other recommendations for routers that can handle gigabit internet access and will have fast processors for ipsec/vpn encryption.
I Don't want to have to build 2 pfSense Xeon boxes that will cost close to $1,000 bucks each, but it doesn't seem like any appliance is powerful enough to handle all the processing.
Also seems like having a processor with AES-NI capability is a must which I don't think any of the "appliance" routers have.
Ideas?
Was using Checkpoint 680 appliances with IPSEC/VPN. Did the job well. iperf3 testing across the link showed full 75 mbit speeds which was my slowest link.
I knew the checkpoints wouldn't keep up with the new speeds but I was surprised to see that they won't even keep up with WAN speeds either just as a firewall. Speed tests showing 450/450 and it's rated at 1.5gb firewall speed. Not using any of the "blades", just firewall.
Tested in my lab (not vpn, just straight firewall connections) and was only getting 500/500 with utilization pegged so these boxes just won't keep up. Again disapointing considering the specs say 1.5Gb/s. For kicks I replaced my test checkpoint box with a Verizon G1100 and did same test and was seeing 800-900 which is about all I figured I was going to get out of a gig connection.
So I've been researching new routers (don't need wifi, handled elsewhere) but they must have ipsec/vpn capability so I can connect both locations. My emphasis needs to be on ipsec/vpn throughput. I really want to saturate the link as much as possible and I understand that ipsec/vpn has all the added overhead of encryption.
One box that I'm going to look at is the ubiquiti ER-4 (or ER-4P as I'm seeing it called in the production release) which is due out this month. Say's it's 4 times faster than the ERPro-8 which is their previous model. I tried to get some VPN tests from the beta testers but nobody had done that testing.
Looking for other recommendations for routers that can handle gigabit internet access and will have fast processors for ipsec/vpn encryption.
I Don't want to have to build 2 pfSense Xeon boxes that will cost close to $1,000 bucks each, but it doesn't seem like any appliance is powerful enough to handle all the processing.
Also seems like having a processor with AES-NI capability is a must which I don't think any of the "appliance" routers have.
Ideas?
Last edited: