FW/IPSec VPN Buyer’s Guide
2. Predictable Performance |
|
| |||
|
|
|
|
|
|
Ability to process traffic of |
|
|
|
| |
varying packet sizes to meet | Yes, |
|
| ||
the performance | See Tolly Reports for |
|
| ||
requirements of the network | third party verification |
|
| ||
Accelerates intensive | Yes, including custom |
|
| ||
processing with hardware | security ASICs |
|
| ||
Ability to support applications |
|
|
|
| |
with a low tolerance for | Yes, hardware is |
|
| ||
latency/jitter, such as VoIP, | optimized for streamlined |
|
| ||
multimedia, etc. | processing |
|
| ||
Fast session ramp rates to | Yes, Dedicated hardware, |
|
| ||
protect against DoS attacks | allowing separate paths |
|
| ||
|
| for session set up and |
|
| |
|
| established flows |
|
| |
|
| Yes, |
|
| |
Provide additional | • ASIC/FPGAs offload |
|
| ||
intensive processing, |
|
| |||
functionality without | making CPU available |
|
| ||
degrading performance | for new/additional |
|
| ||
|
| functions |
|
| |
|
| • Programmability in |
|
| |
|
| ASIC to accelerate |
|
| |
|
| future functions |
|
| |
Turning on all applications |
|
|
|
| |
does not affect the solutions | See spec sheets for |
|
| ||
ability to meet the | performance numbers |
|
| ||
performance needs of the |
|
|
|
| |
deployment |
|
|
|
| |
Traffic prioritization to ensure |
|
|
|
| |
business critical applications |
|
|
|
| |
are available | Yes |
|
| ||
Deliver Quality of Service |
|
|
|
| |
(QoS): |
|
|
|
| |
o Control bandwidth | Yes |
|
| ||
o Set priority field in | Yes |
|
| ||
the Type of Service |
|
|
|
| |
(TOS) byte to reflect |
|
|
|
| |
traffic class priority |
|
|
|
| |
VPN Specific |
|
|
|
| |
Accelerate IKE |
| Yes, OS and Hardware |
|
| Purpose built solutions can |
negotiations for quick |
| designed specifically to |
|
| develop process efficiencies |
tunnel set up |
| negotiate security |
|
| over general purpose OS’ |
|
| associations |
|
|
|
Minimal latency to ensure |
| Yes, |
|
| Unnecessary traversals of |
| o Provides fast path for |
|
| PCI busses is a common | |
not degraded: |
| established flows |
|
| problem with |
|
| o Packets are quickly |
|
| platforms using VPN |
|
| processed without |
|
| acceleration cards, adding |
|
| unnecessary |
|
| latency to application. |
|
| traversals of PCI |
|
|
|
|
| busses |
|
|
|
Maintain large numbers of |
|
|
|
|
|
tunnels to ensure |
| Yes |
|
|
|
availability |
|
|
|
|
|
Copyright © 2004, Juniper Networks, Inc. | 12 |