04-16-2004 03:17 PM - edited 02-20-2020 11:21 PM
PIX 6.3.3
Performance and throughput might be compromised when defining VLAN on a physical interface?.
How much the tagging/untagging operation is critical in performance?
There is a lot of difference between:
1) interface ethernet1 auto
interface ethernet1 vlan18 physical
and
2) interface ethernet1 auto
Tahnks!
04-19-2004 06:53 AM
I have not noted any significant performance degradation on a pix using vlan ieee 802.1q tagging. The org. that I work for uses a pix 515 as a firewall interface to the vpn gateways and that pix is configured to use vlan tagging.
However I would not recommend that you allow the interface to use auto negotiation. I have seen issues with that, with or without vlan tagging, so I would rather see you code interface ethernet1 100full, or 10full instead of auto.
I hope this helps, Ed Hirsel
04-19-2004 08:14 AM
thanks!
we try to use a pix 525 with 6 feth interfaces, for inter-vlan routing between 12 vlan.
davide
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide