Solved

Cisco Router vs ASA

Posted on 2010-09-02
11
727 Views
Last Modified: 2012-05-10
If I need to setup a gateway to connect to other office, support remote mobile client and external access for internal servers through NAT, should I buy a Cisco Router or ASA ? Any comment ?

Thanks
0
Comment
Question by:AXISHK
  • 4
  • 2
  • 2
  • +3
11 Comments
 

Expert Comment

by:Ventsi_Venkov
ID: 33593868
You need Cisco Router, ASA is good Firewall but do not have routing capabilities.
Cisco Router can work as firewall and it can route your ip packets in right direction.
0
 
LVL 9

Accepted Solution

by:
ffleisma earned 250 total points
ID: 33594605
ASA can do routing. I'd say go for an ASA for its firewall features, can handle site-to-site vpn and remote clinet vpn plus it can do the routing for your internal network.



hope this helps :-)
0
 
LVL 9

Expert Comment

by:ffleisma
ID: 33594627
attached is screenshot, i was able to configure internal routing on my ASA.
ASA-routing.JPG
0
Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

 

Author Comment

by:AXISHK
ID: 33594671
For firewall feature in ASA, is it come with ASA or it is add-in servcie that I will to additionally pay for ?

For router, it could also do site VPN to VPN setup, correct ?

Tks
0
 

Assisted Solution

by:aralaci11
aralaci11 earned 125 total points
ID: 33594691
if you are not going to use gre and vti tunnels , then you may choose ASA
0
 

Expert Comment

by:aralaci11
ID: 33594754
12 . ios has site-to-ste vpn without additional license in 15.ios you must have aditional license
for the asa if you want vpn 3des/aes capabilities you shoul by additional license  
0
 
LVL 2

Assisted Solution

by:nblancpain
nblancpain earned 125 total points
ID: 33595429
Both equipement will do almost the same things.
ASA will have less flexibility in terms of available interfaces (DSL, E1, T3...) but more advanced VPN features such as terminating VoIP secure sessions.
Look at the pricing, because both might serve your needs as well (include FW licence and other features needed like IPS, SRST and other SSL/VPN 10 users packs)
0
 
LVL 3

Expert Comment

by:Mystique_87
ID: 33596586
You can take either one of them, as you can configure both with the nat capabilities and remote access VPN. But if security comes into picture, I think its best you go for a firewall
0
 
LVL 9

Assisted Solution

by:ffleisma
ffleisma earned 250 total points
ID: 33596974
as it this would be your gateway, then security would come in mind, routing you won't have any problems using both. for VPN, you can do site-to-site and remote client on both, also you can do GRE on ASA. if your not expecting "major major" routing action going on, then ASA would be the way to go as it serves as your firewall.

it would be striking a balance to your needs so hope we helped :-)
0
 
LVL 9

Expert Comment

by:ffleisma
ID: 33596992
forgot to answer your question. yes router can do a site-to-site as well, and by default ASA is a firewall so basic offering has firewall capabilities. routers have firewall IOS capabilities as well, depends on what IOS you choose.

hope this helps :-)
0
 
LVL 2

Expert Comment

by:nblancpain
ID: 33598632
These 2 are really close. Really check if you need exotic interfaces that would point to a router.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Telepresence on backup 3 33
IPv6 question 1 32
CTRL-Break and putty/special commands/break do not work on Cisco device CLI 3 40
EIGRP Bandwidth 9 20
If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

861 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question