Solved

Cisco ASA 5505

Posted on 2009-05-15
4
486 Views
Last Modified: 2012-05-07
I was wondering if anybody could give me some advice - there will be three servers (web/mail/TS) in a data centre, we are thinking of putting them behind ASA 5505 firewall - there won't be any local users and any VPN connections - all access will be from the outside - I'm comfortable in saying that ASA's 10000 concurrent connection limit would be fine.
As I understand it - ASA's 10 user limit is based on translation table what should be just fine in our case (6 static translations) - the only concern I have is performance.
Can anybody advise on it?

thanks

 
0
Comment
Question by:rxal
  • 2
  • 2
4 Comments
 
LVL 4

Accepted Solution

by:
lkraven earned 250 total points
ID: 24398149
With no VPN in place, the ASA 5505 is capable of an aggregate 150Mbps.  I don't know the size of your uplink to the internet, but I suspect that you will saturate it well before the ASA will hit any bandwidth limitations.

The 10 "user" limit is based on the number of IP addresses behind the firewall, so you won't run into that as an issue either.

Transit time through the ASA 5505 is not much different from any other security appliance-- you will add a hop, but the box itself doesn't add much more latency than other firewall appliances that cost less than $10k.

It seems to me that the ASA is ideally suited for this particular use, IF you want to stay with Cisco.  If not, there are a variety of other good options, Fortinet and Juniper being two I favor, but once it's set up, they'll all be very good choices, the ASA 5505 included.
0
 

Author Comment

by:rxal
ID: 24419794
thanks lkraven - the servers will be on 100MBit/100Mbit uplink what I believe won't be of any problem

By the way are they much different to PIX firewalls in terms of setup?
 

0
 
LVL 4

Expert Comment

by:lkraven
ID: 24423839
The ASA CLI continues to get more and more IOS like, but if you are familiar with how the Pix works, it is not very much different.
0
 

Author Comment

by:rxal
ID: 24439667
ok - the more IOS like the better for me as to be honest I didn't like the differences between PIX CLI and Routers CLI - thanks again
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Join & Write a Comment

Cisco Pix/ASA hairpinning The term, hairpinning, comes from the fact that the traffic comes from one source into a router or similar device, makes a U-turn, and goes back the same way it came. Visualize this and you will see something that looks …
This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now