Solved

Cisco ASA 5505

Posted on 2009-05-15
4
487 Views
Last Modified: 2012-05-07
I was wondering if anybody could give me some advice - there will be three servers (web/mail/TS) in a data centre, we are thinking of putting them behind ASA 5505 firewall - there won't be any local users and any VPN connections - all access will be from the outside - I'm comfortable in saying that ASA's 10000 concurrent connection limit would be fine.
As I understand it - ASA's 10 user limit is based on translation table what should be just fine in our case (6 static translations) - the only concern I have is performance.
Can anybody advise on it?

thanks

 
0
Comment
Question by:rxal
  • 2
  • 2
4 Comments
 
LVL 4

Accepted Solution

by:
lkraven earned 250 total points
ID: 24398149
With no VPN in place, the ASA 5505 is capable of an aggregate 150Mbps.  I don't know the size of your uplink to the internet, but I suspect that you will saturate it well before the ASA will hit any bandwidth limitations.

The 10 "user" limit is based on the number of IP addresses behind the firewall, so you won't run into that as an issue either.

Transit time through the ASA 5505 is not much different from any other security appliance-- you will add a hop, but the box itself doesn't add much more latency than other firewall appliances that cost less than $10k.

It seems to me that the ASA is ideally suited for this particular use, IF you want to stay with Cisco.  If not, there are a variety of other good options, Fortinet and Juniper being two I favor, but once it's set up, they'll all be very good choices, the ASA 5505 included.
0
 

Author Comment

by:rxal
ID: 24419794
thanks lkraven - the servers will be on 100MBit/100Mbit uplink what I believe won't be of any problem

By the way are they much different to PIX firewalls in terms of setup?
 

0
 
LVL 4

Expert Comment

by:lkraven
ID: 24423839
The ASA CLI continues to get more and more IOS like, but if you are familiar with how the Pix works, it is not very much different.
0
 

Author Comment

by:rxal
ID: 24439667
ok - the more IOS like the better for me as to be honest I didn't like the differences between PIX CLI and Routers CLI - thanks again
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Netgear switch to Cisco switch VLAN not passing traffic 8 35
Cisco AnyConnect SBL and system software deployments 2 44
Cisco Switch Port Security 2 37
BGP Code 12 42
This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now