J
J
JukeBox2011-03-04 02:37:11
Computer networks
JukeBox, 2011-03-04 02:37:11

What tsiska to choose?

There is a rack rented in DC, about 10 servers. You need to choose a cisco or a solution on several ciscos for this rack for the following tasks: IP telephony, clients from outside (let there be 1000 sip users), WEB Internet access, mail servers (max 10 gigabytes per day of incoming traffic), from 10 to 50 ipsec tunnels (max speed required by one tunnel is 256kb), redundancy (failover), firewall functions.

It seems to be an ideal option, but not possible due to the cost: 2x Cisco 2801, 2xCisco ASA 5510
Option 1: 2x Cisco 2801 (minuses - limited capabilities of NAT, firewall, but Ipsec can do it normally)
Option 2: 2x Cisco ASA 5510 (no PBR - the main disadvantage, because there will be several external ip)
Option 3: Cisco 2801, followed by ASA. No reservation.

AS no, incl. all sorts of BGP and routing, more complicated than manually prescribed routes, are not needed.

The main tasks are to remove all servers for pieces of iron, keep a couple of dozen ipsec tunnels, be able to PBR and cope with the load.

There is little experience with ciscos, incl. maybe the options above are all very bad. Who will advise what? Who will say anything about the load?

Of course, I would like everything in one, as in D-Link DFL =)

Answer the question

In order to leave comments, you need to log in

2 answer(s)
S
shef, 2011-03-04
@shef

I would recommend you look around. Juniper Networks has a very worthy platform - SRX . In terms of performance / functionality, it is very good and ~ the same in the price range as Cisco. If you want to use IPSec, then you need to carefully consider the supported encryption algorithms - Cisco had big problems with the import of cryptographic tools into the territory of the Russian Federation (hence the problems with delivery, or there are models of hardware where the coprocessor responsible for encryption is missing). I don’t know how Juniper is being imported now;)
At least it’s worth looking and asking around.

S
shadowalone, 2011-03-04
@shadowalone

why not option 2x7301?

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question