[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] RE: [FW1] Limit for FW Management Stations
50??! Wow, that would be long policy install... My number is a bit more conservative. From a management/complexity/capability standpoint 12 or more is usually a Provider-1 candidate. I have seen sites with up to 20 modules running off of the same management station. Most if not all of these sites had 150+ rules, all sorts of funky NAT rules, and generally mass confusion. The human element also plays into this equation, many of us know how much fun it is to deal with multiple megabyte objects.C files, and 200+ rules. If youll be managing 8 firewalls, and that will be it, one management console will be just fine usually (ymmv) If you have 8 now, and know youll have 20+ by next year, you might want to consider multiple management servers (yech) or Provider-1. Other than what I mentioned above, it really depends on what your going to use the firewalls for. Frank -----Original Message----- From: Michael Hernandez [mailto:[email protected]] Sent: Tuesday, September 05, 2000 4:06 PM To: 'Derek Winkler'; Fw-1-Mailinglist (E-mail) Subject: RE: [FW1] Limit for FW Management Stations In theory the cap has always been 50 fw modules per fw management servers, then you would use provider-1.. --Michael -----Original Message----- From: Derek Winkler [mailto:[email protected]] Sent: Tuesday, September 05, 2000 3:45 PM To: Fw-1-Mailinglist (E-mail) Subject: [FW1] Limit for FW Management Stations Is there a practical limit to the number of firewalls a FW mgmt station can handle? I know there's going to be some questions of traffic and server specs. Want to manage 8 Nokia 440 firewalls from a dual 800 MHz, 1 GB memory, 18 GB disk space NT server. Don't have a good handle on the amount of traffic yet. Any comments welcome, Derek Winkler Senior Security Specialist Application Hosting Group 724 Solutions Inc. 4101 Yonge Street Suite 702 Toronto ON Canada M2P 1N6 Telephone:Cell:Fax:Email: [email protected] ============================================================================ ==== To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ============================================================================ ==== ============================================================================ ==== To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ============================================================================ ==== ================================================================================ To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================================================
|