Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

UTM performance: The yo-yo effect

November 2, 2009 03:01 AM ET

Network World - In our testing of the SonicWALL TZ200 and TZ210 systems, we discovered a significant performance impact when UTM features were enabled on typical Internet traffic. SonicWALL's specification sheets warn that there will be a reduction. For example, the TZ200 data sheet has a typical Internet performance specification of 50Mbps (our tests actually turn it in closer to 100Mbps) and UTM performance of 35Mbps, a 30% drop. But our testing showed a much heavier impact, with the TZ200 turning in only about one-third of its rated UTM number. What gives?

The answer isn't tremendously complicated, but it provides some key buying strategies for network managers interested in UTM firewalls. SonicWALL's explanation is that some malware signatures were added to the firewall, and this caused the performance slowdown. We've heard the same story in every industry that uses signatures: intrusion prevention, antimalware, and antispam. The result is a yo-yo of performance, with new signatures temporarily causing a slowdown until a faster approach is identified, followed by a speedup — until the next slowdown.

In our test, we happened to catch SonicWALL at the low point of its performance, but this teaches a good lesson: don't buy security appliances hoping that you'll always get consistent performance matching the specification sheets. Just as antivirus vendors can and do occasionally send out a bad update that blocks everything or nothing, security products can and do suffer from periodic slowdowns.

In our testing, we find that a typical worst-case performance for many of the firewalls that go through our lab is a 10:1 ratio. When they're at their best, with no UTM features on, they are often 10 times faster than when they're most stressed out with high levels of traffic and all UTM features enabled. There are no guarantees, of course, but this suggests that a fairly safe rule of thumb is to select products that have unfiltered performance ratings about 10 times as fast as your expected normal traffic load.

This suggests that firewall buyers who intend to use UTM features should consider very carefully the performance specifications of devices they're evaluating. Antimalware features such as antivirus tend to have the highest impact, with intrusion-prevention system features somewhere in the middle, and content filtering (URL filtering) generally having the lightest impact of all. If you’re going to check all the boxes and turn on all the protections, make sure you keep in mind our 10-to-1 rule when picking the firewall for your network.

Return to test.


Reprinted with permission from

For more information about enterprise networking, go to NetworkWorld.com
Story copyright 2009 Network World, Inc. All rights reserved.

Jump to comments

Security

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...