Re: [load balancing] Verisign and Load Balancers

From: Alex Samonte (asamonteIZZATsitesmith.com)
Date: Fri Feb 16 2001 - 19:27:33 EST

  • Next message: Alex Samonte: "Re: [load balancing] Verisign and Load Balancers"

    On Fri, Feb 16, 2001 at 08:26:46AM -0800, Vincent Power wrote:
    > The last time I talked to f5 (a few months ago) the BigIP could only use one
    > SSL card at a time, but this is suppose to change in the next major software
    > release.

    This is a recent code fix they did. Unfortunately, the F5 itself can't handle
    much more than 200 conn/s anyways. The rainbow cards do not do the bulk
    encryption/decryption of packets. That's left for the general purpose
    CPU to do. At 200 conn/s the F5's cpu is pegged at 100% utilized.

    And you also want it to handle all your non encrypted load balancing too.
    Not much CPU left for that.

    It's a serious flaw in having the SSL accelerator inline with all of
    your non SSL traffic.

    -Alex



    This archive was generated by hypermail 2b30 : Fri Feb 16 2001 - 19:31:27 EST