D
D
Dmitry Sidorov2012-07-04 07:44:52
VPN
Dmitry Sidorov, 2012-07-04 07:44:52

Which Cisco router to choose or other options?

We have:
— Central office. A network of up to 50 computers with Internet access through a proxy. Network on Active Directory.
- Several remote offices for 3-5 computers with direct Internet access.
— Mail server on the Internet.
What I want:
- Buy a Cisco router. Help with the choice. Or an option is to install a separate machine (or a virtual one on XEN) with *nix (CentOS or FreeBSD?) and use iptables and openVPN.
- Connect remote offices to the central office network via VPN and bring it into AD. What equipment to use in remote offices (Cisco, it seems to me, is a little expensive for this).
- Put a separate machine (or virtual on XEN) with *nix (CentOS or FreeBSD?). Install postfix, squid, etc. for the proxy server (remote offices must also go through the proxy server) and the mail server. Why on a separate machine from "iptables" - because both the mail and proxy servers will use synchronization with AD.
- Preferably the cheapest and most customizable options (from the expensive one, most likely I can only beg Cisco).

I myself am an avid Windows admin. I worked with networks “insofar as”, but we need to develop.

Please criticize, advise, help in choosing. Thank you!

UPD: Perhaps, in the future, we want to connect a backup Internet channel, so I would like to ADDITIONALLY consider Cisco options with two WAN ports or with the ability to reassign ports and / or expand with additional modules.

Answer the question

In order to leave comments, you need to log in

10 answer(s)
A
Alexey, 2012-07-04
@Doomsday_nxt

Look also vyatta, there are a lot of how to in Russian on the internet. It has been in production for several years now. At first there was a Cisco 2811, but her fan was noisy. I took it off and while I was looking for a replacement for the fan (whoever changed it knows, you will find their horseradish) temporarily put vyatta on the virtual machine. Since then, 2 years have passed, Cisco is still in the closet.

A
alexey2000, 2012-07-04
@aleksey2000

I would put ASA5505 everywhere and put site2site and anyconnect on them (in the main office)

C
chopik, 2012-07-04
@chopik

As an option cisco 28xx series. And there are expansion slots and can build channels (and only if the K9 series) and eigrp understands. In general, not a bad series - just for your needs. I use 2801 myself.

R
rgaliull, 2012-07-04
@rgaliull

V-zero: the router is not made in the virtual machine.
First: since there are two inputs, there should be two devices.
Secondly, it is important to know what the load on the VPN will be, it depends on the bandwidth of the channel.
You can buy used Cisco, Juniper.
If there is no money, then Mikrotik. He can also use OpenVPN.
To set it up, it’s better to ask specialists, at the same time you will learn if you force the documentation to be issued.

H
Hayden, 2012-07-05
@Hayden

Cisco 28xx / 35xx to the office, to Mikrotiki 751G branches, we do this, we don’t get sick. Mikrotiks are more than enough for a small office for VPN (including VoIP), DHCP, encrypted Wifi and much more. Doesn't itch at all.

A
Alexey, 2012-07-06
@wireshark

If we put cats and the budget is not very large, then it is possible at flea markets like avito, Cisco 2801 for 10 tr. take.

B
Busla, 2012-07-04
@Busla

And what at remote offices now costs as the gateway?

N
Nikolai Turnaviotov, 2012-07-04
@foxmuldercp

If there is a 2008R2 server - vpn, routing, nat on it according to accounts in AD + vpn the client is in each version of Windows.
If not - vyatta and linux / bsd on the server and openvpn on Windows at regional offices.
Mail - if it glows outward, then it will be available regardless of the VPN connection.
PS The router is normally done in a virtual machine with two network forwarding - if the hypervisor falls, then believe me, there will be no time for a proxy, and if the virtual machine falls - frya and Linux in the minimum configuration weigh several hundred meters, it takes a minute to raise from backup. Even a 30 gigabyte Windows virtual machine rises quickly.

C
chopik, 2012-07-05
@chopik

In general, the UC series for branches is not very bad, not for large ones, but let's say small and medium ones. There already both voip and voice mail. Their only minus is not supported by eigrp, although it needs to be clarified, maybe they have already added it in new models / ios.

A
Alexander, 2016-01-15
@skusnov

In the head office ISR4321-SEC / K9 (namely SEC) without it, VPN cannot be thrown. To offices C881-K9 .
Or head ASA5512-K8 + license L-ASA5512-SEC-PL to offices ASA5505-SEC-BUN-K9 The second option is more classic.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question