3 Site VPN advice

Hi,

Just a bit of advice, I have 3 offices (1 HQ + 2 remote) which I want to connect together across a site to site VPN.

HQ office will host a small database and the other 2 remote offices will require a secure access to the database across a VPN.

I was planning to use the below scenario;

HQ – Cisco PIX 506e + Cisco 1700 series

Remote Office x 2 Cisco PIX 506e + Cisco 1700 series

Site to Site VPN

I suspect the above scenario is okay, but could I get away with just using the PIXs or would it be better to stop with the full scenario?

Thanks
logga1Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

BennooCommented:
you can get a 1700 series with vpn ios
this will not be as good as a pix,
but will be cheaper
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
JoesmailCommented:
Im not sure what the bandwidth requirements are but for the above scanario two 501's should be fine for the remote offices.  The 1700 would be a good central vpn device.

0
ImmediateActionCommented:
just thought i would add that you may need to use RDP via the VPN if the database transfer speed is not desirable.
0
How do you know if your security is working?

Protecting your business doesn’t have to mean sifting through endless alerts and notifications. With WatchGuard Total Security Suite, you can feel confident that your business is secure, meaning you can get back to the things that have been sitting on your to-do list.

jabiiiCommented:
Since you don't have the equipment yet, if your looking for better alternatives, you might want to look at Juniper NetScreens.
https://www.juniper.net/products/integrated/

but your config above would work.
0
nickhillsCommented:
we use 501's all round  - at remote offices and HQ.

works a charm if your demand is not excessive

regards,
Nick
0
BennooCommented:
Summary

Best Option
506's and 1700's all round

Cheaper Option
501's and 1700's all round

With the best option, you get better throughput and more
expandability.
0
jabiiiCommented:
umm 501 doesn't have the throughput Juniper does, unless you buy extras unless theve changed in the last month or so...
ref this.
http://www.experts-exchange.com/Networking/Broadband/VPN/Q_21704713.html
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.