Base System - Compaq 117755-003 - ProSignia - 740 White Paper

Performance analysis and tuning of raptor’s eagle nt 3.06 firewall on compaq servers
Hide thumbs Also See for 117755-003 - ProSignia - 740:
Table of Contents

Advertisement

278A/0497
W
P
HITE
APER
(cont.)
. .
. .
. .
The -y switch disables DNS lookups of source addresses when HTTP analyzes incoming
. .
. .
connections. Default installations do not use this switch.
. .
. .
The -z switch disables DNS lookups of destination addresses when HTTP analyzes
. .
incoming connections. Default installations do not use this switch.
. .
. .
. .
In using these switches to gain performance on HTTP transfers, some restrictions do apply:
. .
. .
Alert thresholds for all HTTP rules are disabled. This is not usually a problem. Since HTTP
. .
traffic is so bursty by nature, even the highest alert thresholds are often exceeded.
. .
. .
. .
HTTP connections do not appear in Hawk's Gateway window. This is not usually a problem
. .
since HTTP connections are so short-lived.
. .
. .
. .
HTTP connections that have exceeded a time limit or time range are not automatically killed.
. .
. .
Messages in the Eagle log file do not display the number of the rule being used.
. .
. .
. .
Number of rules used or rule base
. .
. .
The NSTL setup requires a minimum of 4 rules, which are used for most tests. Rule sets of 100
. .
. .
were also used to compare the performance difference in scanning the rule base.
. .
. .
. .
Protocols used during test configurations
. .
. .
. .
Tests are done using FTP and HTTP protocols and just the HTTP protocol. In both sets of tests a
. .
base system is used and the software and hardware difference is measured from the base system.
. .
. .
. .
MaxReceive buffer changes on the NetFlx-3 NIC cards
. .
. .
. .
Using the Windows NT Registry:
. .
. .
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cpqnf3(#)\Parameters
. .
. .
Add the following parameter:
. .
. .
MaxReceives = REG_DWORD 0x1F4 = 500
. .
. .
. .
Increases the number of MaxReceives counters for Compaq Netelligent 10/100TX Network
. .
Controller to 500. (The default is 100.)
. .
. .
Specifies the maximum number of receive lists the driver allocates for receive frames
. .
. .
. .
. .

Base System

. .
ProLiant 5000 system
. .
. .
1-Pentium Pro 200 MHz Processor, 512K cache
. .
. .
64 MB RAM
. .
2-EISA NetFlx-3 Network Interface Cards
. .
. .
PCI Smart/2-Array controller, 1Disk, Raid 0
. .
MaxReceive Buffer for NetFlx-3 cards equals 100
. .
. .
100 Mb Network
. .
HTTP cache is ON
. .
. .
DNS Lookups for HTTP is ON
. .
. .
. .
. .
. .
. .
. .
. .
.
12

Advertisement

Table of Contents
loading

Table of Contents