FW/IPSec VPN Buyer’s Guide

2. Predictable Performance

 

 

 

 

 

 

 

 

Ability to process traffic of

 

 

 

 

varying packet sizes to meet

Yes,

 

 

the performance

See Tolly Reports for

 

 

requirements of the network

third party verification

 

 

Accelerates intensive

Yes, including custom

 

 

processing with hardware

security ASICs

 

 

Ability to support applications

 

 

 

 

with a low tolerance for

Yes, hardware is

 

 

latency/jitter, such as VoIP,

optimized for streamlined

 

 

multimedia, etc.

processing

 

 

Fast session ramp rates to

Yes, Dedicated hardware,

 

 

protect against DoS attacks

allowing separate paths

 

 

 

 

for session set up and

 

 

 

 

established flows

 

 

 

 

Yes,

 

 

Provide additional

• ASIC/FPGAs offload

 

 

intensive processing,

 

 

functionality without

making CPU available

 

 

degrading performance

for new/additional

 

 

 

 

functions

 

 

 

 

• Programmability in

 

 

 

 

ASIC to accelerate

 

 

 

 

future functions

 

 

Turning on all applications

 

 

 

 

does not affect the solutions

See spec sheets for

 

 

ability to meet the

performance numbers

 

 

performance needs of the

 

 

 

 

deployment

 

 

 

 

Traffic prioritization to ensure

 

 

 

 

business critical applications

 

 

 

 

are available

Yes

 

 

Deliver Quality of Service

 

 

 

 

(QoS):

 

 

 

 

o Control bandwidth

Yes

 

 

o Set priority field in

Yes

 

 

the Type of Service

 

 

 

 

(TOS) byte to reflect

 

 

 

 

traffic class priority

 

 

 

 

VPN Specific

 

 

 

 

Accelerate IKE

 

Yes, OS and Hardware

 

 

Purpose built solutions can

negotiations for quick

 

designed specifically to

 

 

develop process efficiencies

tunnel set up

 

negotiate security

 

 

over general purpose OS’

 

 

associations

 

 

 

Minimal latency to ensure

 

Yes,

 

 

Unnecessary traversals of

real-time applications are

 

o Provides fast path for

 

 

PCI busses is a common

not degraded:

 

established flows

 

 

problem with PC-based

 

 

o Packets are quickly

 

 

platforms using VPN

 

 

processed without

 

 

acceleration cards, adding

 

 

unnecessary

 

 

latency to application.

 

 

traversals of PCI

 

 

 

 

 

busses

 

 

 

Maintain large numbers of

 

 

 

 

 

tunnels to ensure

 

Yes

 

 

 

availability

 

 

 

 

 

Copyright © 2004, Juniper Networks, Inc.

12

Page 12
Image 12
Juniper Networks 710008-001 manual Predictable Performance