Blog Home  Home Feed your aggregator (RSS 2.0)  
IMFirewall Blog - Monday, April 20, 2009
Block Internet Access,Block P2P,Web Filtering
 
# Monday, April 20, 2009

WFilter Monitoring Performance

WFilter is designed to monitor a network with no more than 1000 computers, and the available internet bandwidth of the entire network shall be no more than 100Mbit/s.

Since WFilter is software, the performance depends a lot on the hardware performance. Higher bandwidth requires faster CPU, and more monitored computers require more RAM. Therefore, we recommend you to provide 1M available RAM for each monitored computer.

Below is a performance test result for HTTP request of WFilter 3.3 file-based version:


#ComputersBandwidthTotal HTTP RequestsRecorded PercentCPUMemory
15037.2M16000100%35%260,298K
210035M20000100%38%280,576K
320031M40000100%58%294,561K
440033M80000100%68%372,786K
560032.3M120000100%80%540,151K
6100032.6M20000060%99%540,664K

As we can see from the above table, when monitored computers number reachs 1000, the "recorded percent" decreased to 60% suddenly. And we noticed the memory only slightly increased, so it shall because lack of memory. Therefore we added the monitoring computer RAM to 2G, and do the test again:

#ComputersBandwidthTotal HTTP RequestsRecorded PercentCPUMemory
7100032.7M200000100%90%820,640K

And the test of WFilter 3.3 database version(SQL Server) performance has the similar result:

#ComputersBandwidthTotal HTTP RequestsRecorded PercentCPUMemory
15034.9M10000100%45%197,392K
210034.9M20000100%45%210,196K
320031M40000100%45%270,960K
440032.9M80000100%45%364,234K
5100028.6M20000058.84%100%540,664K

The performance of 1000-user can also be improved by adding RAM of the monitoring computer.

Test Environment

1Network100M ethernet
2Test ClientIntel(R) pentium(R) Dual 1.80+1.80GHz , 1G RAM
3Test Monitoring ServerIntel(R) Celeron(R) 2.66GHz, 1G RAM
4WFilter VersionWFilter 3.3
5SwitchTplink TL-SF1008



Monday, April 20, 2009 7:34:35 AM (GMT Daylight Time, UTC+01:00)    Block Messenger | Block P2P | Chat Monitor | Content Filter | Deployment | How to block p2p | How to block websites  |   |  Trackback
# Wednesday, January 07, 2009
  WFilter 3.3 is under alpha testing now. The new version will add "Bandwidth limit", "Url keywords blocking", "Website visit quota" and other exciting features.
  1. "Bandwidth limit". You can set bandwidth limit for each computer, or blocking certain internet traffic when internet bandwidth is too high. This feature can help you to manage company bandwidth flexibly.
  2. "Url Keywords Blocking", blocking url/webpage by keywords category. You may use this feature to block certain keywords from being searched in search engines.
  3. "Website visit quota", by this feature, you are able to set visit time quota for each website category. For example, "news" websites can be limited to "1 hour" for each day.


 

Wednesday, January 07, 2009 5:37:21 AM (GMT Standard Time, UTC+00:00)    Block Messenger | Block P2P | Chat Monitor | Content Filter | dasBlog | Deployment | How to block p2p | How to block websites  |   |  Trackback
# Thursday, December 25, 2008
     It is said that Google talk uses Jabber protocol to communicate.
     However, Google talk has more flexible ways to connect:
     1. Using Jabber standard tcp port 5222.
     2. Using TLS port 443.
     3. Using web chatting on port 80.

     So you will not able to block Google talk by simply blocking Jabber standard port. And 443, 80 ports are essential internet ports which shall not be blocked.

     WFilter makes it simple to block google talk. Google talk connections can be identified and blocked by signature matching. And all these can be done just by one click as below:



     More information, please refer to: http://www.imfirewall.com/en/protocols/Jabber.htm.

Thursday, December 25, 2008 5:01:43 AM (GMT Standard Time, UTC+00:00)    Block Messenger | Chat Monitor  |   |  Trackback
# Thursday, May 15, 2008

Some websites, like facebook, youtube, are rather time consumable.

If you do nothing to filter certain websites, your employees may spend several hours a day on web surfing.

So How to block certain websites to save your productivity?

1. Some router/gateway might have the ability to block certain websites.

2. Firewall appliances, like cisco PIX, will also be a good choice.

3. The third, you can choose internet filtering software to do web filter and blocking.

 

 

 

Thursday, May 15, 2008 11:56:13 AM (GMT Daylight Time, UTC+01:00)    Content Filter | How to block websites  |   |  Trackback
# Monday, April 28, 2008

Most employees waste more than an hour on browsing web pages. Even worse, someone will not be able to concentrate on their work during work time.
So, to save productivity, it is necessary for organizations to block certain websites and restrict internet access.

In my opinion, things should be done from several aspects:

1. Only work-related websites are allowed during work time.
2. Destructive websites like violence, adult, shall be blocked always.
3. Downloading websites shall be blocked to save bandwidth if you are suffering from slow internet speed.

For those companies who are very strict with websites browsing, you can implement a website whitelist, by which, only websites in the whitelist can be visited.

More information, please refer to internet blocking and internet monitoring.

Monday, April 28, 2008 7:28:05 AM (GMT Daylight Time, UTC+01:00)    Block Messenger | Block P2P | Content Filter | How to block websites  |   |  Trackback
# Saturday, April 19, 2008

Block MSN file transfer: impossible mission?

  It is convenient to transfer files via messengers like msn/live, yahoo, icq...  But it is also necessary for organizations to block unauthorized file transfers to keep their networks safe.

  However, messenger software uses several ways to avoid being blocked. They use dynamic ports, encrypted connections, variety connection type to bypass network firewall.

  Let me take msn as an example. By our test, there have four type of msn file transfer as described below:

  1. For two buddies, if one of them is connected to internet directly, direct connection will be established to transfer files. This is the quickest way. There has three type of direct connections with dynamic ports which is negotiated by two sides.

  1.1) Direct TCP connection.

  1.2) Direct TCP connection use TLS encryption.

  1.3) Direct UDP transmission.

  2. If direct connection can not be established, msn servers can act as a relay server to transfer files. The file transfer packets will be among with normal msn messages.

  As you can see from above, there is no way to block msn file transfer simply by blocking some ports in the firewall. The firewall should be smart enough to recognize msn file transfer direct connections, and it shall be able to pick up file transfer packets from normal msn messages.

  Block MSN File Transfer

  Internet Monitor

  Block P2P

 

 

Saturday, April 19, 2008 6:49:52 AM (GMT Daylight Time, UTC+01:00)    Block Messenger  |   |  Trackback
Copyright © 2012 IMFirewall Software. All rights reserved.
DasBlog 'Portal' theme by Johnny Hughes.
Pick a theme: