RFC 2647 (rfc2647) - Page 2 of 26


Benchmarking Terminology for Firewall Performance



Alternative Format: Original Text Document



RFC 2647            Firewall Performance Terminology         August 1999


   3.27 Rule set....................................................20
   3.28 Security association........................................20
   3.29 Stateful packet filtering...................................21
   3.30 Tri-homed...................................................22
   3.31 Unit of transfer............................................22
   3.32 Unprotected network.........................................23
   3.33 User........................................................23
   4. Security considerations.......................................24
   5. References....................................................25
   6. Acknowledgments...............................................25
   7. Contact Information...........................................25
   8. Full Copyright Statement......................................26

1. Introduction

   This document defines terms used in measuring the performance of
   firewalls. It extends the terminology already used for benchmarking
   routers and switches with definitions specific to firewalls.

   Forwarding rate and connection-oriented measurements are the primary
   metrics used in this document.

   Why do we need firewall performance measurements? First, despite the
   rapid rise in firewall deployment, there is no standard method of
   performance measurement. Second, implementations vary widely, making
   it difficult to do direct performance comparisons. Finally, more and
   more organizations are deploying firewalls on internal networks
   operating at relatively high speeds, while most firewall
   implementations remain optimized for use over relatively low-speed
   wide-area connections. As a result, users are often unsure whether
   the products they buy will stand up to relatively heavy loads.

2. Existing definitions

   This document uses the conceptual framework established in RFCs 1242
   and 2544 (for routers) and RFC 2285 (for switches). The router and
   switch documents contain discussions of several terms relevant to
   benchmarking the performance of firewalls. Readers should consult the
   router and switch documents before making use of this document.

   This document uses the definition format described in RFC 1242,
   Section 2. The sections in each definition are: definition,
   discussion, measurement units (optional), issues (optional), and
   cross-references.







Newman                       Informational