- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sizing guide: intra-vlan routing speed
Hi,
Having recently split a flat network into VLANs, I am noticing reduced througput with inter-vlan routing. This is hardly surprising. I'm using an MX84, which has a 'statefull firewall throughput' advertised at 500 Mbps. [MX84 Datasheet]
Conveniently, this MX is due to be replaced in the next few months, so I'm wondering which model can provide 1Gbps inter-vlan routing. Looking at the current sizing guide [link] I'm unsure about the differences between the descriptions of the top 3 columns.
- I assume 'max throughput with all security features enabled' is WAN throughput?
- And 'Max stateful (L3) firewall throughput in passthrough mode' is inter-VLAN routed firewall throughput?
Have I got that right?
So, assuming I have a 1Gbps WAN circuit, and also want 1Gbps inter-vlan routing, and want to achieve these speeds on both, the minimum model I would pick is the MX95?
Thanks in advance.
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes IDS/IPS is all or nothing.
Ips, amp,content filtering are part of the adv sec license. If you dont have that or use it you can look at the mx 75/85.
If you want the 1Gbit with adv sec then you could consider the mx95
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Passthrough mode is L2
Nat mode is Layer3 (lan to wan, possible vlan to vlan).
security features can also be between VLAN for example IDS/IPS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks. I'm using my current MX84 in NAT mode, so I now see I need to be looking at the 3rd line when comparing the MX84 to other devices with regard to inter-vlan routing throughput.
You mention "security features can also be between VLAN for example IDP/IPS". As far I understand, IDP/IPS is always enabled between VLANs and there is no way to disable this, correct?
In answer to my own question, it seems the the MX95 is the lowest device to offer 1Gbps WAN speeds and minimum inter-vlan routing speeds of 1Gbps. Please correct me if I'm wrong.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes IDS/IPS is all or nothing.
Ips, amp,content filtering are part of the adv sec license. If you dont have that or use it you can look at the mx 75/85.
If you want the 1Gbit with adv sec then you could consider the mx95
