On Fri, Feb 16, 2001 at 08:26:46AM -0800, Vincent Power wrote:
> The last time I talked to f5 (a few months ago) the BigIP could only use one
> SSL card at a time, but this is suppose to change in the next major software
> release.
This is a recent code fix they did. Unfortunately, the F5 itself can't handle
much more than 200 conn/s anyways. The rainbow cards do not do the bulk
encryption/decryption of packets. That's left for the general purpose
CPU to do. At 200 conn/s the F5's cpu is pegged at 100% utilized.
And you also want it to handle all your non encrypted load balancing too.
Not much CPU left for that.
It's a serious flaw in having the SSL accelerator inline with all of
your non SSL traffic.
-Alex
This archive was generated by hypermail 2b30 : Fri Feb 16 2001 - 19:31:27 EST