I have a bit of a dilemma. I am doing work on a very large client network (50,000 clients).
The backend is all private IP (dhcp), so at some point we have to NAT out.
We've hit two bottlenecks. First, is the dhcp server, the second is the appliance we use to NAT.
I had to fill in someone else's shoes, but lets just say the current appliance was a bad choice (Citrix Netscaler). I do know that they tried to NAT in their 7604 (Sup720), and the load was way too much.
Since some security was needed, my initial thoughs are an ASA 5550 (or mutliple 5550's). Just curious as to how well these units could handle a very very large NAT load of traffic.
As for the dhcp server, its a Sun box. I'm curious, but would using a
3800 series router be any better in performance. The current dhcp server is dealing with 30,000 clients at any time, plus handling existing/expiring leases. i.e. the dhcp lease file is over 100Mb. We're running isc-dhcp.