Solved

What SSG model for 55 IPSEC Tunnels?

Posted on 2013-02-02
7
293 Views
Last Modified: 2013-02-03
I have 54 branch offices and need each one to VPN to a central location.  Would an SSG140 work for this?  Could it also handle logging for the VPN traffic?
0
Comment
Question by:dhuff2012
  • 4
  • 2
7 Comments
 
LVL 11

Expert Comment

by:MajorBigDeal
ID: 38847905
In terms of number of sessions, yes.

http://www.networkscreen.com/SSG140.asp?gclid=CM3tlrOembUCFcODQgodQQUAOQ

under the specifications tab the maximum number of concurrent sessions is 48,000.
0
 

Author Comment

by:dhuff2012
ID: 38847953
Would this also be scalable for up to 200 VPN's?
0
 
LVL 11

Expert Comment

by:MajorBigDeal
ID: 38847973
Yes, assuming that the total amount of bandwidth is within the limits of the box.
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 11

Expert Comment

by:MajorBigDeal
ID: 38847977
The max vpn tunnels is 500 so 200 is not a problem.
0
 
LVL 11

Expert Comment

by:MajorBigDeal
ID: 38847981
I just noticed the logging part of your question.  It does support some logging and monitoring.  But if you want to get more sophisticated it can use a syslog server.
0
 
LVL 68

Accepted Solution

by:
Qlemo earned 500 total points
ID: 38848438
The SSG140 will work if you do not want or need to use route-based VPN (versus policy-based). It allows for 50 (static) tunnel interfaces only (the 500 are concurrent VPN tunnels, which are the sum of all route- and policy-based VPNs active at the same time).

In most cases you will use policy-based VPNs, but there are some scenarios you'll need tunnel interfaces, e.g. if you want to use one tunnel for non-consecutive target network addresses.

In regard of logging you will probably want to set up a syslog server, as recommended already, unless you are interested in traffic stats only (not sessions).
0
 

Author Closing Comment

by:dhuff2012
ID: 38848928
Thank you.  That was the exact info I needed.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

When you connect to your workplace's VPN, you may not notice that you are using your workplace's servers to serve up webpages.  This might be undesirable since the workplace can log all the places you've been.  It also might be very slow to load pag…
Like many others, when I created a Windows 2008 RRAS VPN server, I connected via PPTP, and still do, but there are problems that can arise from solely using PPTP.  One particular problem was that the CFO of the company used a Virgin Broadband Wirele…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now