OVERKILL
$100 Site Donor 2021
I'm considering getting an ASA5510. I had a 5505 before but sold it after the NFR timeout was up.
My original plan was to get a 1921 or a 1941 (ISR) but I think it may make more sense to get an ASA instead, as what it would be replacing at this point (a Juniper SSG5) is a security appliance.
These firewalls do NAT better than the ISR's anyway and I'm natting 3x different VLAN's into 3x different subnets along with terminating multiple IPSEC VPN endpoints and the ASA's have a lot more horsepower.
http://www.cisco.com/cisco/web/support/model/tsd_hardware_asa_model_5510.html#0
It'll NAT 300Mbit, do 170Mbit of VPN throughput, up to 130,000 concurrent sessions...etc
Their blurb:
Originally Posted By: Cisco
Cisco ASA 5510 Adaptive Security Appliance
The Cisco ASA 5510 Adaptive Security Appliance delivers advanced security and networking services for small and medium-sized businesses and enterprise remote/branch offices in an easy-to-deploy, cost-effective appliance. These services can be easily managed and monitored by the integrated Cisco ASDM application, thus reducing the overall deployment and operations costs associated with providing this high level of security. The Cisco ASA 5510 Adaptive Security Appliance provides high-performance firewall and VPN services and five integrated 10/100 Fast Ethernet interfaces. It optionally provides high-performance intrusion prevention and worm mitigation services through the AIP SSM, or comprehensive malware protection services through the CSC SSM. This unique combination of services on a single platform makes the Cisco ASA 5510 an excellent choice for businesses requiring a cost-effective, extensible, DMZ-enabled security solution.
Though I find this line a bit interesting:
Originally Posted By: Cisco
As business needs grow, customers can install a Security Plus license, upgrading two of the Cisco ASA 5510 Adaptive Security Appliance interfaces to Gigabit Ethernet and enabling integration into switched network environments through VLAN support.
So it has two ports that are Gig-E but aren't Gig-E unless you buy the license
And it supports 50 VLAN's, or you can have 100 if you again, buy the extra license
My original plan was to get a 1921 or a 1941 (ISR) but I think it may make more sense to get an ASA instead, as what it would be replacing at this point (a Juniper SSG5) is a security appliance.
These firewalls do NAT better than the ISR's anyway and I'm natting 3x different VLAN's into 3x different subnets along with terminating multiple IPSEC VPN endpoints and the ASA's have a lot more horsepower.
http://www.cisco.com/cisco/web/support/model/tsd_hardware_asa_model_5510.html#0
It'll NAT 300Mbit, do 170Mbit of VPN throughput, up to 130,000 concurrent sessions...etc
Their blurb:
Originally Posted By: Cisco
Cisco ASA 5510 Adaptive Security Appliance
The Cisco ASA 5510 Adaptive Security Appliance delivers advanced security and networking services for small and medium-sized businesses and enterprise remote/branch offices in an easy-to-deploy, cost-effective appliance. These services can be easily managed and monitored by the integrated Cisco ASDM application, thus reducing the overall deployment and operations costs associated with providing this high level of security. The Cisco ASA 5510 Adaptive Security Appliance provides high-performance firewall and VPN services and five integrated 10/100 Fast Ethernet interfaces. It optionally provides high-performance intrusion prevention and worm mitigation services through the AIP SSM, or comprehensive malware protection services through the CSC SSM. This unique combination of services on a single platform makes the Cisco ASA 5510 an excellent choice for businesses requiring a cost-effective, extensible, DMZ-enabled security solution.
Though I find this line a bit interesting:
Originally Posted By: Cisco
As business needs grow, customers can install a Security Plus license, upgrading two of the Cisco ASA 5510 Adaptive Security Appliance interfaces to Gigabit Ethernet and enabling integration into switched network environments through VLAN support.
So it has two ports that are Gig-E but aren't Gig-E unless you buy the license
And it supports 50 VLAN's, or you can have 100 if you again, buy the extra license