CISCO ASA /PIX devices


This should be an easy question for firewall experts.

we have a 515e PIX that has 3 Physical interfaces (e0, e1 and e2). I assigned security levels to the interfaces. e0=0 e1=100 e2=10.

We are looking into replacing it with an ASA device.

(1) Which models would provide me with at least those 3 physical interfaces to configure those security zones?. . I get a little confused with some ASA models that come with switch ports integrated.

(2) You might also provide me with some basic "education"  about the physical and virtual interfaces on those devices.

Thanks
JohnRamzAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Istvan KalmarHead of IT Security Division Commented:
The ASA and PIX ports configurable to subinterfaces, this means:
You able to make dot1q trunk to the switch, but is less secure than you separate it physycally
0
JohnRamzAuthor Commented:
So it  looks like 5510 and 5520 would provide me at least the same physical interfaces. Right?
0
Big Business Goals? Which KPIs Will Help You

The most successful MSPs rely on metrics – known as key performance indicators (KPIs) – for making informed decisions that help their businesses thrive, rather than just survive. This eBook provides an overview of the most important KPIs used by top MSPs.

JohnRamzAuthor Commented:
Would the 5505 also provide me with at least 3 physical interfaces? I do not care much about the extra security features. I just need at least to be able to configure the 3 Security Zones.

Thanks
0
Istvan KalmarHead of IT Security Division Commented:
yes, but if you want gigabitethernet buy 5520, if you want 5 fastethernet on 5510 buy ASA 5510 Firewall Edition Bundle
0
JohnRamzAuthor Commented:
What about 5505?
0
JohnRamzAuthor Commented:
Anybody else out there that could tell me if the 5505 model would work to configure at least 3 physical interfaces with different security levels? Thanks
0
Istvan KalmarHead of IT Security Division Commented:
HI,

If you buy 5505, you able to configure 3 security level, becouse it has restricted licence, it means the third zone only one direction can be make traffic!!!!

If you want all zone traffic you must buy ASA5505-SEC-BUN-K9

Cisco ASA 5505 Firewall Edition Unlimited-user Security Plus, 8-port Fast Ethernet switch, 25 IPsec VPN and 2 SSL VPN peers, DMZ, stateless Active/Standby
high availability, 3DES/AES
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
ForsakenSACommented:
Yes the ASA 5505 will work.  I would suggest buying the security plus add-on.

Here is some info from Cisco.

The Cisco ASA 5505 features a flexible 8-port 10/100 Fast Ethernet switch, whose ports can be dynamically grouped to create up to three separate VLANs for home, business, and Internet traffic for improved network segmentation and security.  

You could seperate the VLANs to be DMZ, LAN and Internet.

Continuing on:

As business needs grow, customers can install a Security Plus upgrade license, enabling the Cisco ASA 5505 to scale to support a higher connection capacity and up to 25 IPsec VPN users, add full DMZ support, and integrate into switched network environments through VLAN trunking support.

This just means you can actually extend the DMZ into you LAN by using Vlanning.  This will depend how your DMZ setup is at the moment and how many devices are connected?  Seperate switch, single device?

Basically with Vlanning you can have multiple virtual networks over a singal physical network.  

I hope this helps.
0
JohnRamzAuthor Commented:
Thanks for your help
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Cisco

From novice to tech pro — start learning today.