Wanguard 6.2 User Guide
Wanguard Installation
Packet Filter Hardware Requirements
Packet Sniffing Capacity
1 Gbit/s – 1,400,000 packets/s
10 Gbit/s – 14,000,000 packets/s
Architecture
64-bit x86
64-bit x86
CPU
2.4 GHz Xeon
3.2 GHz quad-core Xeon (e.g. Intel X5672)
RAM
2 GB
8 GB
NICs
1 x Gigabit Ethernet (with driver supported
by PF_RING)
1 x Fast Ethernet for management
1 x 10 GbE adapter (Chelsio T4/T5, Silicom
Intelligent Director or Intel 82599 chipset)
1 x Fast Ethernet for management
HDDs
2 x 5200 RPM HDD, RAID 1, 35 GB
2 x 5200 RPM HDD, RAD 1, 35 GB
The main task of Packet Filter is to inspect the packets sent to the attacked destinations and to generate
filtering rules that isolate the malicious traffic. For packet inspection, Packet Filter uses the same capturing engines
also used by Packet Sensor. To load-balance Packet Filter on multiple CPU cores, use the same configuration required
by Packet Sensor.
When a filtering rule is generated, Packet Filter can report it and apply it on the local software firewall
(NetFilter), in-NIC hardware filter, BGP FlowSpec-capable router or third-party filtering appliance.
The software firewall used by Packet Filter does not use the connection tracking mechanism specific to
stateful firewalls or IPSes, and this ensures a much better filtering and routing performance during spoofed attacks
and SYN floods. However, the filtering and packet-forwarding capacity may not be line-rate during powerful attacks
with small packets.
The hardware filters supported by Packet Filter permit 10Gbps line-rate packet filtering on:
➢
Chelsio T4/T5 network adapters. Packet Filter can program 486 LE-TCAM filter rules that block traffic
towards source/destination IPv4/IPv6 addresses, source/destination TCP/UDP port and IP protocol.
➢
Intel 82599 chipset network adapters, such as Intel X520, Intel X540, HP X560. Packet Filter can program
4096 filter rules that block source or destination IPv4 addresses.
➢
Silicom Intelligent Director adapters.
To increase the packet filtering capacity to 40 Gbit/s, 100 Gbit/s or more, define a Filter Cluster that
aggregates multiple Packet Filters running on different servers equipped with 10 Gbit/s network adapters. To split
and distribute the traffic evenly, use a hardware load balancer or equal-cost multipath routing.
Flow Filter Hardware Requirements
The hardware requirements for Flow Filter are very low because the traffic information was already pre-
aggregated by Flow Sensor. If Flow Filter is used only for reporting and not for software/hardware packet filtering,
run it on the same server that runs the Console.
Flow Filter can apply filtering rules just like Packet Filter. The requirements for software-based and/or
hardware-based traffic filtering are listed in the Packet Filter Hardware Requirements section.
- 16 -
Summary of Contents for wanguard 6.2
Page 1: ......