Thinking about a new firewall.....

Status
Not open for further replies.

OVERKILL

$100 Site Donor 2021
Joined
Apr 28, 2008
Messages
63,434
Location
Ontario, Canada
I'm considering getting an ASA5510. I had a 5505 before but sold it after the NFR timeout was up.

My original plan was to get a 1921 or a 1941 (ISR) but I think it may make more sense to get an ASA instead, as what it would be replacing at this point (a Juniper SSG5) is a security appliance.

These firewalls do NAT better than the ISR's anyway and I'm natting 3x different VLAN's into 3x different subnets along with terminating multiple IPSEC VPN endpoints and the ASA's have a lot more horsepower.

http://www.cisco.com/cisco/web/support/model/tsd_hardware_asa_model_5510.html#0

asa5510_photo.JPG


It'll NAT 300Mbit, do 170Mbit of VPN throughput, up to 130,000 concurrent sessions...etc

Their blurb:

Originally Posted By: Cisco
Cisco ASA 5510 Adaptive Security Appliance
The Cisco ASA 5510 Adaptive Security Appliance delivers advanced security and networking services for small and medium-sized businesses and enterprise remote/branch offices in an easy-to-deploy, cost-effective appliance. These services can be easily managed and monitored by the integrated Cisco ASDM application, thus reducing the overall deployment and operations costs associated with providing this high level of security. The Cisco ASA 5510 Adaptive Security Appliance provides high-performance firewall and VPN services and five integrated 10/100 Fast Ethernet interfaces. It optionally provides high-performance intrusion prevention and worm mitigation services through the AIP SSM, or comprehensive malware protection services through the CSC SSM. This unique combination of services on a single platform makes the Cisco ASA 5510 an excellent choice for businesses requiring a cost-effective, extensible, DMZ-enabled security solution.



Though I find this line a bit interesting:

Originally Posted By: Cisco
As business needs grow, customers can install a Security Plus license, upgrading two of the Cisco ASA 5510 Adaptive Security Appliance interfaces to Gigabit Ethernet and enabling integration into switched network environments through VLAN support.


So it has two ports that are Gig-E but aren't Gig-E unless you buy the license
smirk.gif


And it supports 50 VLAN's, or you can have 100 if you again, buy the extra license
wink.gif
 
I will add though that I've got a TON of 1921's in service and they will NAT 100+Mbit (they have a pair of Gig-E interfaces) and are significantly more economical.... ARG!
 
I'm studying to get my CCNA now and have several years experience small businesses, But your budget obviously is larger than any of those I have worked with.

I think you have the right idea. It sounds like you need the extra horsepower these can provide.
If it's not in the budget you can use both the 1921's and the 5510's, with the extra horsepower where needed, in different applications as to mitigate cost.

What you are saying makes perfect sense to me.
 
To be clear, this is for my home LAN/lab Dave, I can get one on an NFR for "testing" purposes, so the price isn't as bad as it would initially appear. But that applies to the 1921 too, which would be even less expensive.

The WAN connection (at this time) wouldn't tax either of them, but I am fond of the extra features the ASA provides... I'm just not sure it is worth the price difference.
21.gif
 
Ahh. Well in that case all you have to do is ask "Is the cost would be worth the freedom to tinker at will with it?"

Only a question that you can answer.
thumbsup2.gif
 
Just got my price from my distributor after getting the approval from Cisco. Looks like I'm getting the ASA 5510.
smile.gif
 
ASA 5510 should be here tomorrow or Thursday. Then I have to port over all my subnets, VPN profiles...etc
smile.gif
 
Got the new firewall setup last night.

Updated to the latest software after getting all my connections setup (9.1.1r4) and it randomly reboots when torrents are running. CPU usage is low, memory usage is low....

So just rolled back the software to 9.0.2ED, we'll see if this fixes it.

BTW, this was NOT made in China. It was made in Mexico..... Funky! I was hoping it would be made in the USA like that last switch I brought in.
 
Originally Posted By: Brons2
I got a 5515-X just to run AnyConnect, so a 5510 for your usage scenario seems justified
wink.gif



NICE!!
thumbsup2.gif


How long have you had it for?
 
I should clarify...it's not mine personally but the only thing we're doing at work with it is running VPN. We have a pair of 5520s doing the firewall work.
 
Originally Posted By: Brons2
I should clarify...it's not mine personally but the only thing we're doing at work with it is running VPN. We have a pair of 5520s doing the firewall work.


Gotcha! That's some pretty decent gear, how big is the office? I assume the one is just a fail-over for the other?
 
Status
Not open for further replies.
Back
Top Bottom