Solved

CISCO ASA /PIX devices

Posted on 2009-07-08
10
384 Views
Last Modified: 2012-05-07

This should be an easy question for firewall experts.

we have a 515e PIX that has 3 Physical interfaces (e0, e1 and e2). I assigned security levels to the interfaces. e0=0 e1=100 e2=10.

We are looking into replacing it with an ASA device.

(1) Which models would provide me with at least those 3 physical interfaces to configure those security zones?. . I get a little confused with some ASA models that come with switch ports integrated.

(2) You might also provide me with some basic "education"  about the physical and virtual interfaces on those devices.

Thanks
0
Comment
Question by:JohnRamz
  • 5
  • 4
10 Comments
 
LVL 34

Expert Comment

by:Istvan Kalmar
Comment Utility
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
Comment Utility
The ASA and PIX ports configurable to subinterfaces, this means:
You able to make dot1q trunk to the switch, but is less secure than you separate it physycally
0
 

Author Comment

by:JohnRamz
Comment Utility
So it  looks like 5510 and 5520 would provide me at least the same physical interfaces. Right?
0
 

Author Comment

by:JohnRamz
Comment Utility
Would the 5505 also provide me with at least 3 physical interfaces? I do not care much about the extra security features. I just need at least to be able to configure the 3 Security Zones.

Thanks
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
Comment Utility
yes, but if you want gigabitethernet buy 5520, if you want 5 fastethernet on 5510 buy ASA 5510 Firewall Edition Bundle
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:JohnRamz
Comment Utility
What about 5505?
0
 

Author Comment

by:JohnRamz
Comment Utility
Anybody else out there that could tell me if the 5505 model would work to configure at least 3 physical interfaces with different security levels? Thanks
0
 
LVL 34

Accepted Solution

by:
Istvan Kalmar earned 500 total points
Comment Utility
HI,

If you buy 5505, you able to configure 3 security level, becouse it has restricted licence, it means the third zone only one direction can be make traffic!!!!

If you want all zone traffic you must buy ASA5505-SEC-BUN-K9

Cisco ASA 5505 Firewall Edition Unlimited-user Security Plus, 8-port Fast Ethernet switch, 25 IPsec VPN and 2 SSL VPN peers, DMZ, stateless Active/Standby
high availability, 3DES/AES
0
 
LVL 1

Expert Comment

by:ForsakenSA
Comment Utility
Yes the ASA 5505 will work.  I would suggest buying the security plus add-on.

Here is some info from Cisco.

The Cisco ASA 5505 features a flexible 8-port 10/100 Fast Ethernet switch, whose ports can be dynamically grouped to create up to three separate VLANs for home, business, and Internet traffic for improved network segmentation and security.  

You could seperate the VLANs to be DMZ, LAN and Internet.

Continuing on:

As business needs grow, customers can install a Security Plus upgrade license, enabling the Cisco ASA 5505 to scale to support a higher connection capacity and up to 25 IPsec VPN users, add full DMZ support, and integrate into switched network environments through VLAN trunking support.

This just means you can actually extend the DMZ into you LAN by using Vlanning.  This will depend how your DMZ setup is at the moment and how many devices are connected?  Seperate switch, single device?

Basically with Vlanning you can have multiple virtual networks over a singal physical network.  

I hope this helps.
0
 

Author Closing Comment

by:JohnRamz
Comment Utility
Thanks for your help
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now