RB953GS-5HnT
http://routerboard.com/RB953GS-5HnT
for that, we would first have to test the existing models, so that one can compare. We currently only have IPsec tests for CCRIPSEC performance info would be very nice to know.
3DES-MD5, AES-128-MD5 and SHA1
older (and current on MIPS) models are struggling with SHA1...and IPSEC overall ..
Would appreciate if you can do a WAN-to-LAN NAT throughput test (with regular stateful firewall rules) on the RB953GSHave some here, which test would you like to know? Have a couple 953's, and CCR1009-8G-1S, CCR1016-12G not in production yet (will go soon) so I don't mind carrying out some tests.
The standard Stateful Firewall ... i.e. allow Established & Related and drop InvalidWhich kind of rules? feel free to post in export format the fw rules.
Also, you mean the typical NAT scenario (natting a class C or whatever to one external IP??)
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1 to-addresses=0.0.0.0
/ip firewall connection tracking set enabled=yes
/ip firewall filter
add chain=forward protocol=tcp connection-state=invalid \
action=drop comment="drop invalid connections"
add chain=forward connection-state=established action=accept \
comment="allow already established connections"
add chain=forward connection-state=related action=accept \
comment="allow related connections"