Hello
I would like to replace in the near future, my central firewall.
It is a 2011-RM-UAS and is configured as the following:
a) port 6-7 “core switchgroup”
b) port 5 giga uplink to backbone network
c) port 9, routed port to a subnet
The router doesnt do NAT, it has:
a) conntrack
b) about 101 simple queues
c) basic firewall (packet filter from outside and from inside to protect worms etc) (about 20rules)
The core switchgroup is connected to two routers, one fiber 30/30 and a backup dsl 7m/700
the router has mangle rules to choose who goes to fiber and who to adsl.
On the port 5 we have 3 VVRP IP.
I have cpu load of about 80% in peak hours. I would like to replace the RB with something more powerful.
I would like to 1100hx2 because it is dual core and I could assign a core to switch0 and another one to switch1 to reduce irq (they are not so high but less is better)
I am concerned about noise… better a 1200 ?