 |

01-23-2007, 05:45 PM
|
|
Senior Member
|
|
Join Date: Mar 2006
Location: UK
Posts: 120
|
|
Quote:
Originally Posted by simby
read my post. We are home users, and we dont have p2p restriction. Have you ever have a security attack, dos and other? Have you?! Have you check status?
|
So how many ip's do you have at present? and how many concurrent connections?
__________________
2x Astaro ASG320 in Cluster Mode (Active/Active)
normally at latest patch level.
|

01-23-2007, 05:52 PM
|
 |
Senior Member
|
|
Join Date: May 2006
Posts: 124
|
|
Quote:
Originally Posted by Godsbrother
So how many ip's do you have at present? and how many concurrent connections?
|
I have no problem with 10 IP and i agree with IP limit to 10. This OK, it is for home use.
BTW I have: 2PC (my + sister), 1 laptop + 1 "server" for personal u. - testing and 1 xbox360 connected to internet.
What I don t agree is CURRENT 1000 connection. This firewall not a home mini router. BTW, home router for 50$ can have 600 curent connection.
I recomend NOT TO LIMIT CURRENT CONNECTION.
__________________
Asatro Internet Security 6.312
H. info: 3.2Ghz Intel P4 541+, 4096MB, 80GB/7.200 rpm/min SATA
N. info: 2x Realtek n. 10/100, Dlink 24x switch, FTTH (Optical fibers) 10 | 10Mb
I use IPv7 now... It's pretty much IPv6, but the headers contain p0rn. Saves bandwidth.
Last edited by simby; 01-23-2007 at 05:54 PM.
|

01-23-2007, 07:09 PM
|
 |
Member
|
|
Join Date: Jan 2007
Location: Montreal, Canada
Posts: 52
|
|
A small note on concurrent connections
Windows XP SP2 limits concurrent connections to 10 for security purposes. Pre-SP2 the limit was 50 concurrent connections in Windows.
Now....lets do some math.
10 IP's using 10 concurrent connections = 100 concurrent connections
10 IP's using 50 concurrent connections = 500 concurrent connections
Not even near the 1000 concurrent connections limit.
Besides, Bit Torrent will not use over ~32 concurrent connections in a session anyways (this is defined in your Bit Torrent client settings).
I'm more worried about the IP limit, here are my thoughts.....
The 10 IP's should be reserved for devices passing traffic through the firewall, the term for these IP's I believe is "Protected IP's"
For example, the Sonicwall TZ170 device with a 10 user limit allows you to create an exception list of devices/users to exclude from the total device count.
My current home setup includes
Two IP camera's
One server
One streaming media device
One desktop
One Laptop
One wireless access point
One managed Layer2 switch
One LAN connected printer
Total of 9 IP devices, All of which require an IP address (out of ease of use, these use DHCP with static IP's), However only three devices require internet access (In the Sonwall scenario, I'm using 3/10 IP's, all other devices are on the exclusion list and are denied internet access).
If there was a way I could tag devices and exclude them from the "protected IP's list" and have them not count towards the 10 IP limit would be nice.
|

01-23-2007, 07:41 PM
|
 |
Senior Member
|
|
Join Date: May 2006
Posts: 124
|
|
Quote:
Originally Posted by Atticka
A small note on concurrent connections
Windows XP SP2 limits concurrent connections to 10 for security purposes. Pre-SP2 the limit was 50 concurrent connections in Windows.
Now....lets do some math.
10 IP's using 10 concurrent connections = 100 concurrent connections
10 IP's using 50 concurrent connections = 500 concurrent connections
Not even near the 1000 concurrent connections limit.
Besides, Bit Torrent will not use over ~32 concurrent connections in a session anyways (this is defined in your Bit Torrent client settings).
I'm more worried about the IP limit, here are my thoughts.....
The 10 IP's should be reserved for devices passing traffic through the firewall, the term for these IP's I believe is "Protected IP's"
For example, the Sonicwall TZ170 device with a 10 user limit allows you to create an exception list of devices/users to exclude from the total device count.
My current home setup includes
Two IP camera's
One server
One streaming media device
One desktop
One Laptop
One wireless access point
One managed Layer2 switch
One LAN connected printer
Total of 9 IP devices, All of which require an IP address (out of ease of use, these use DHCP with static IP's), However only three devices require internet access (In the Sonwall scenario, I'm using 3/10 IP's, all other devices are on the exclusion list and are denied internet access).
If there was a way I could tag devices and exclude them from the "protected IP's list" and have them not count towards the 10 IP limit would be nice.
|
Why do you use Windows? Have you try linux?
p.s.: i have sonicwall pro 230 and i have unlimit IP and 30.000 limit connection (i have home licens and try to replace with astaro firewall box, but now i dont know,... i need home and in company pro. firewall). With 1 linux torr. conn. on sonicwall box i have cca. 1250 connection. Fort test. Did you ever have any dos attack on line 15Mb +? What can i do with "firewall" who can t protect me?
__________________
Asatro Internet Security 6.312
H. info: 3.2Ghz Intel P4 541+, 4096MB, 80GB/7.200 rpm/min SATA
N. info: 2x Realtek n. 10/100, Dlink 24x switch, FTTH (Optical fibers) 10 | 10Mb
I use IPv7 now... It's pretty much IPv6, but the headers contain p0rn. Saves bandwidth.
Last edited by simby; 01-23-2007 at 08:20 PM.
|

01-23-2007, 09:25 PM
|
|
Moderator
|
|
Join Date: Apr 2001
Location: Brantford, Ontario, Canada
Posts: 806
|
|
What does a DoS attack have to do with outbound concurrent connections? Are you DoS'ing people?
I have probably one of the larger home networks on this forum, with several machines online at any given time, my wife using Emule, myself using BT on two machines, plus playing online gaming.
What do I hit for a max concurrennt connections? Apprioximately 2500. So yes, 1000 is a bit low, but really, how many people have a home network very big?
My office LAN, which has approx. 100 users, barely goes above 1000. Maybe it hits 1100. That is with over 150 machines!
__________________
7 x ASG 220, 4 x ASG 120, 2 x 25 IP, Home Unlimited Power User.
|

01-23-2007, 09:30 PM
|
 |
Senior Member
|
|
Join Date: May 2006
Posts: 124
|
|
If you have limit 10IP, isn t this limit ok? Why would you limit internet connection?
With 1 torrent i have 1200 connection.
How "big" internet line do you have?
About dos attack. Do you have any server? DNS server + attack or email + attack? how many connection, 1000?
Each of these packets are handled like a connection request, causing on 1000 connection limited?
And please read http://en.wikipedia.org/wiki/DOS_attack
__________________
Asatro Internet Security 6.312
H. info: 3.2Ghz Intel P4 541+, 4096MB, 80GB/7.200 rpm/min SATA
N. info: 2x Realtek n. 10/100, Dlink 24x switch, FTTH (Optical fibers) 10 | 10Mb
I use IPv7 now... It's pretty much IPv6, but the headers contain p0rn. Saves bandwidth.
Last edited by simby; 01-23-2007 at 09:39 PM.
|

01-23-2007, 09:37 PM
|
|
Moderator
|
|
Join Date: Apr 2001
Location: Brantford, Ontario, Canada
Posts: 806
|
|
Internet connection = 100 Meg Fiber, full duplex.
Yes I have DNS server, and email, but they are HOME servers. This is a HOME license.
__________________
7 x ASG 220, 4 x ASG 120, 2 x 25 IP, Home Unlimited Power User.
|

01-23-2007, 09:42 PM
|
 |
Member
|
|
Join Date: Jan 2007
Location: Montreal, Canada
Posts: 52
|
|
Ok! lets all pull it out and see who's bigger....
Guys, the point is for the average home user 1000 concurrent connections is more than enough (the two of you are exceptions.....).
Whats worries me more is that IP devices are becoming more and more popular in the home, the 10 IP limit can quickly be met in a house using all the latest gadgets.
Home security, media servers, TiVo's (PVR's), IP enabled appliances, home automation (smart homes), VOIP phones, etc....
Free for home use at 10 IP's with the security services enabled is FANTASTIC, try and find someone else who offers this....you wont, not for freee.
However, maybe a power user license would be ideal for a home user to allow for additional IP's and more concurrent connections, maybe a one time upgrade? Its up to Astaro to decide.
|

01-23-2007, 09:47 PM
|
 |
Senior Member
|
|
Join Date: May 2006
Posts: 124
|
|
I agree, only 1 time, but not more then 50$
__________________
Asatro Internet Security 6.312
H. info: 3.2Ghz Intel P4 541+, 4096MB, 80GB/7.200 rpm/min SATA
N. info: 2x Realtek n. 10/100, Dlink 24x switch, FTTH (Optical fibers) 10 | 10Mb
I use IPv7 now... It's pretty much IPv6, but the headers contain p0rn. Saves bandwidth.
|

01-24-2007, 12:20 AM
|
|
Member
|
|
Join Date: May 2004
Posts: 55
|
|
Well besides doing some "freelance" beta-testing of Astaro software here, some of us test other products as well, beyond the gadget addiction that I have, so it would be ideal to have more than 10 for special cases... I forsee trouble with my network now that enforcement is in place...
here is the current list of devices on my network...
1 Macbook pro (running Parallel's Workstation VM software... more ip's here)
1 Compaq laptop
1 hp laptop
1 Vista Media Center Ultimate Edition system
1 Vista Workstation
1 Windows XP Workstation
1 Windows 2003 Server R2
1 Slingbox
1 Linksys PAP for Vonage
1 HP 2510 IP printer (yes, shouldn't need internet here)
1 PS3
1 PS2
3 Xbox
1 Xbox 360
1 Nintendo Wii
I have ditched a few devices such as Tivo, Replay TV device, and some other media devices. I do have multiple switches and whatnot, but they shouldn't need internet access as well.
So at any given time, I am averaging under 20, and that isn't all at the same time, but the problem is they don't drop off after they access the net...
And before someone says "why not nat some of those"... that isn't a solution, and only a kludge that may work for some.
I guess I will have to start finding another solution that I am willing to PAY FOR!
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT. The time now is 11:27 AM.
| |  |