Solved

Cisco 1721 upgrade to 10Mb Fiber and Amazon VPC

Posted on 2010-08-31
4
924 Views
Last Modified: 2012-05-10
I have a bit of a newb double question on routers which are related.

We're in the process of upgrading our current T1 to a 10 Mb fiber.  From the research that I've done, it looks like I can still buy the WIC-1ENET and MOD1700-VPN cards.  Before I spend the money I want to be sure it can handle a VPN connection to Amazon's VPC and the upgrade to 10Mb fiber.  It looks like the WIC-1ENET can support a 10Mb Ethernet.  

1)  Can anyone confirm if the 1721 VPN is capable of connecting to Amazon's AWS VPC?  
2)  Or if there is a more appropriate product for our network?  Of course, we are hoping to limit costs.

I've noticed that some of the routers include Fiber support (I don't believe the 1721 does?), but is there that much benefit to cutting out the Ethernet/Fiber media converter?  

Locally we have 3 - 24 port and 1 - 16 port, unmanaged Linksys switches (4124, 4116, 3124), connected to the Cisco 1721 with a Watchguard e550 in the middle.  Watchguard also has VPN capabilities but can not handle the BGP routing over a VPN interface, so it'll have to be the router that connects to AWS VPC.  The AWS documentation provides configuration examples for Cisco and Juniper, but I would imagine other's work as well.

During the upgrade to fiber, I'd like to support both connections simultaneously with the T1 in a fail-over capacity, though I could be talked out of this.
0
Comment
Question by:augercast
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 22

Expert Comment

by:Matt V
ID: 33572567

The exact througput of a 860MPC based (1721) Cisco router is based on  a number of factors.  Type of encryption/encapsulation, version of  code, etc.
 
3DES  IPSec router to router "in the lab" with 1400 byte packets came out to  be 8Mb I believe.  If your network isn't "in the lab" you can expect  less (probably much less) than that.

From: https://supportforums.cisco.com/thread/236990

Considering this, you may want to look at an 1800 or even 2800 series to make sure you can actually get 10Mbps through the router.
0
 
LVL 34

Accepted Solution

by:
Istvan Kalmar earned 250 total points
ID: 33573852
HI,

forget 1721 it is a weak router for your scenario, please refer the attachment!

Best regards,
Istvan
routerperformance.pdf
0
 
LVL 2

Assisted Solution

by:nblancpain
nblancpain earned 250 total points
ID: 33574804
Hi,

And this file shows perfs for just CEF routing, with VPN (if used), you don't have hardware encryption in 1721 router, you will get 1 or 2 Mbps max with CPU at 100%.
I strongly advise 2821 or 1941 as minimum router.

Nicolas
0
 

Author Closing Comment

by:augercast
ID: 33631650
Answers were fairly sparse, leaving me to interpret data supplied and no mention was made of connecting to AWS VPC which leaves me assuming when I was looking for confirmation.
0

Featured Post

Are You Headed to Black Hat USA 2017?

Getting ready for Black Hat next week? Kick things off with the WatchGuard Badge Challenge and test your puzzle and cipher skills. Do you have what it takes to earn our limited edition Firebox Badge? Get started today - https://crimsonthorn.net

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Juniper VPN devices are a popular alternative to using Cisco products. Last year I needed to set up an international site-to-site VPN over the Internet, but the client had high security requirements -- FIPS 140. What and Why of FIPS 140 Federa…
Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses
Course of the Month11 days, 10 hours left to enroll

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question