In order to adapt to user's complex circumstances and the demand, also to have “the selling point”, present's firewall has many functions generally, these functions looked alone does not have any question, for instance prepared the function hotly already through the test, the H.323 tendency also tested using the support passes, but in the actual environment, we possibly needed, in prepared in the situation to use the H.323 video frequency conference hotly, and requested when the cut the video frequency did not interrupt, some firewalls were not possibly good, but the similar combination function was actually the user true need. In addition, firewall's function and the performance will appraise independently generally, divide into the function testing and the performance test two parts, whether there is the function testing care single function, the performance test cared that two, three simple applications the performance, will cause the function performance finally “the two layers of skin”, cannot reflect the firewall ability truly: In the test the performance is very high, but many functions cannot use, in actual use, when opens after the commonly used function, the performance becomes very low. Therefore, must unifies the performance and the function appraisal can appraise really the firewall. The concrete appraisal should obtain from the following several aspects:
# 2~7 access control function, the application layer depth filtration, ought to be able to combine the use willfully particularly with the following function: Address mapping, port mapping, VLAN Trunk support, user authentication, dynamic package filtration, flow control and so on;
# the security function, the key point is anti-Synflood. The firewall as the network sole channel, must guarantee that is protected the network the security, whether needs the key inspection safety protection function to guarantee the normal visit during filtration attack, whether to forge source address attack and at the same time real source address attack effective, whether to protect the server to be exempt from the impact. This function ought to be able with the address mapping, the port mapping, VLAN the Trunk support, the user authentication, the dynamic package filtration, the flow control at the same time and so on or combines the use willfully;
# practical performance. The performance test includes 6 principal aspects generally: Volume of goods handled, detention, drop rate, back to back, concurrent connection number, newly built connection speed. The practical performance is the inspection in the close user real service condition performance;
# newly built connection speed, because the network application has the undulatory property to be big, namely the different time visit quantity difference very major characteristic, requests the firewall also to be able to adapt this kind of situation, corresponding consideration target namely newly built connection speed. Considers the user network and the application complexity, but also needs to open the commonly used function, for example: A package of filtration, the content filtration, the anti-attack, in this case test the newly built connection speed. Below introduces in simply the history several model of outstanding firewalls:
Other pages: : 1 * 2 * 3 * 4 * 5 * 6 * 7 * Next>>
|