Re: Network oriented services with FreeBSD

From: Bob Martin (bob_at_buckhorn.net)
Date: 03/26/05

  • Next message: Suporte Matik: "Re: Network oriented services with FreeBSD"
    Date: Sat, 26 Mar 2005 08:53:05 -0600
    To: laurent LF <laurent_lists@yahoo.fr>
    
    

    We do all of our routing and firewalls with FreeBSD, instead of
    dedicated equipment like Cisco. In short, a Xeon based PC (we're using
    mostly ~2ghz, single processor boxen) that can be bought for less than a
    $1000 will do almost anything a $15,000 dollar name brand router will
    do. And it will do a few things the named brand units wont, like traffic
    analysis. Instead of having the dedicated equipment and a server, we
    just have a server.

    Most of our servers are in data centers, so a simple NIC handles the
    Internet pipe. We do have a couple of boxen with T1 cards, and one with
    a T3 card. The prices of the cards are higher than you would pay for
    dedicated hardware blades, but the TCO is still much lower.

    We don't do QoS. But I've talked to several folks that have had good
    luck with 5.3 and ALTQ. You can do some pretty amazing things with
    netgraph and dummy net, QoS should be pretty simple.

    FreeBSD isn't, to my knowledge, easily clustered. I know we don't have
    anything like LVS. But you can use FreeBSD to balance requests to a
    server farm.

    Like anything, you have to define the job, then the results, and see
    what works.

    Bob Martin

    laurent LF wrote:

    > Well, of course my question is too vague.
    > Typically, I would be interested to know if people use
    > FreeBSD boxen as routers, firewalls, for bandwidth
    > management / QoS, service load-balancing (like LVS for
    > example) or that kind of stuff in an ISP environment.
    > In which cases people prefer FreeBSD to a dedicated
    > hardware, why and on which scale. (why you prefer a
    > FreeBSD box to a 3660 or 7200 for example and for
    > which usage)
    >
    > I know lots of things can be done but I would like to
    > hear real life examples.
    >
    > Thanks,
    >
    > Laurent
    >
    > --- Bob Martin <bob@buckhorn.net> wrote:
    >
    >>The devil is in the details here...
    >>How good/scalable as compared to what?
    >>
    >>It does l2tp, but there is a much, much better
    >>protocol.. SSH. It will
    >>also terminate isakmp.
    >>
    >>Network load balancing? You mean balancing pipe? Or
    >>services?
    >>
    >>We replaced our 3660's and 7200's with FreeBSD boxen
    >>2 years ago. We've
    >>never missed them.
    >>
    >>But, like all things, FreeBSD can't be everything to
    >>everyone. YMMV
    >>
    >>Bob Martin
    >
    >
    >
    >
    >
    >
    >
    >
    > __________________________________________________________________
    > Découvrez le nouveau Yahoo! Mail : 250 Mo d'espace de stockage pour vos mails !
    > Créez votre Yahoo! Mail sur http://fr.mail.yahoo.com/
    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"


  • Next message: Suporte Matik: "Re: Network oriented services with FreeBSD"

    Relevant Pages

    • RE: Network oriented services with FreeBSD
      ... >> dedicated equipment like Cisco. ... > probably not a fair comparism since your $15K router will ... > Lots of things IOS can do FreeBSd can still not, as CEF, ...
      (freebsd-isp)
    • RE: freebsd-questions Digest, Vol 52, Issue 3
      ... To subscribe or unsubscribe via the World Wide Web, ... bypassing a proxy server ... > As some of you may recall, I'm engaged in an ongoing saga trying to set> up a FreeBSD machine on a school's network. ...
      (freebsd-questions)
    • Re: Question
      ... >I am a network manager for a small government. ... >proprietary to something like FreeBSD or linux? ... Are server needs are currently simple and we only have one NT4 server ...
      (freebsd-newbies)
    • RE: FreeBSD Security Survey
      ... Your also ignoring the fact that many security holes are a lot ... queries to this server to the NAS only. ... server with a new version of FreeBSD. ... Your survey responses lack any responses that indicate that leaving ...
      (freebsd-questions)
    • Re: freebsd reseller
      ... 2000 for workstations and 2000 Server for servers. ... FreeBSD and OpenBSD. ... When I try to install dvips I get the following ... >> I'm not at all familiar with firewire stuff. ...
      (freebsd-questions)