I think this is a very bad idea, do you have any chance of creating a separate VLAN that does not require IDS, make it for iSCSI data only?
-----Original Message----- From: owner-toasters@mathworks.com [mailto:owner-toasters@mathworks.com] On Behalf Of Tom Yates Sent: Thursday, March 20, 2008 10:34 AM To: toasters@mathworks.com Subject: Performance impact of in-lined firewalls/IDS
I have a bunch of filers that we use from various hosts for CIFS, NFS and iSCSI. Powers That Be are planning to put both a firewall and an adaptive IDS between my filers and my hosts.
Does anyone have any rough and ready (ir ndeed, shiny and precise) numbers about what sort of performance impact this can have, recommendations for
how to do it properly, or indeed solid data suggesting not to do it at all? Any experience with this?