Skip the navigation
Opinion

UTM performance: The yo-yo effect

By Joel Snyder
November 2, 2009 03:01 AM ET

Network World - In our testing of the SonicWALL TZ200 and TZ210 systems, we discovered a significant performance impact when UTM features were enabled on typical Internet traffic. SonicWALL's specification sheets warn that there will be a reduction. For example, the TZ200 data sheet has a typical Internet performance specification of 50Mbps (our tests actually turn it in closer to 100Mbps) and UTM performance of 35Mbps, a 30% drop. But our testing showed a much heavier impact, with the TZ200 turning in only about one-third of its rated UTM number. What gives?

The answer isn't tremendously complicated, but it provides some key buying strategies for network managers interested in UTM firewalls. SonicWALL's explanation is that some malware signatures were added to the firewall, and this caused the performance slowdown. We've heard the same story in every industry that uses signatures: intrusion prevention, antimalware, and antispam. The result is a yo-yo of performance, with new signatures temporarily causing a slowdown until a faster approach is identified, followed by a speedup — until the next slowdown.

In our test, we happened to catch SonicWALL at the low point of its performance, but this teaches a good lesson: don't buy security appliances hoping that you'll always get consistent performance matching the specification sheets. Just as antivirus vendors can and do occasionally send out a bad update that blocks everything or nothing, security products can and do suffer from periodic slowdowns.

In our testing, we find that a typical worst-case performance for many of the firewalls that go through our lab is a 10:1 ratio. When they're at their best, with no UTM features on, they are often 10 times faster than when they're most stressed out with high levels of traffic and all UTM features enabled. There are no guarantees, of course, but this suggests that a fairly safe rule of thumb is to select products that have unfiltered performance ratings about 10 times as fast as your expected normal traffic load.

This suggests that firewall buyers who intend to use UTM features should consider very carefully the performance specifications of devices they're evaluating. Antimalware features such as antivirus tend to have the highest impact, with intrusion-prevention system features somewhere in the middle, and content filtering (URL filtering) generally having the lightest impact of all. If you’re going to check all the boxes and turn on all the protections, make sure you keep in mind our 10-to-1 rule when picking the firewall for your network.

Return to test.

Originally published on www.networkworld.com. Click here to read the original story.
Reprinted with permission from NetworkWorld.com. Story copyright 2010 Network World, Inc. All rights reserved.
Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
All Security White Papers
Security Webcasts
Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
Introduction to VMware vCenter Site Recovery Manager 5
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
The Top Ten Secrets to Avoiding SAN Performance Problems
Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
Deduplication Without Compromise
Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
Director of Disk Products Discusses DXi6700
Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs