Can you fit 500M of rules into a firewall? - Boris Lytochkin - EuroBSDcon 2024
HTML-код
- Опубликовано: 2 дек 2024
- We use FreeBSD as a base OS for our routers, firewalls and VPN gateways in our enterprise network. Ipfw is used to filter traffic between our employees' devices and servers located in our DCs as well as on the Internet. Having more than 65 thousand unique usernames, different filtering policies for wired/wireless/vpn environments, we pack 500 millions of elementary rules (e.g. allow tcp from user@entry_media to myserver 443) into a single router running FreeBSD and ipfw. One single box handles up to 10Gbit/s of traffic.
In my talk I give you a bird's eye view of our approach and share some hints to unleash the full potential of ipfw.