ā08-02-2022 02:46 PM
Hi all,
I'm new to Cisco Firewalls, and I have questions about enterprise network design, so the requirements are:
- VPN site to site and remote access for 100 user.
- IP packets Inspection.
- Supports IPS and IDS.
- Supports routing between internal networks (OSPF, IEGRP, RIP) We may need BGP in the future.
- And what is the recommended management tool for this device Maybe in the future we will add some cisco devices to the network, Currently, we are using Netgear switches and Mikrotik routers.
I searched for a while to see which firewall fits these requirements and got this Cisco ASA 5525-x firewall but I have never used Cisco before, I need your help to decide.
Thank you so much for your advice!
Solved! Go to Solution.
ā08-03-2022 05:46 AM
The 2100 series will give you everything that your requirements specify and will allow for future expansion. Again, depending on your future network plans, I would recommend considering the FPR2130 or FPR2140as this will give you an option to install a 10Gig SFP module if you at some point would require this.
ā08-02-2022 06:08 PM - edited ā08-02-2022 06:08 PM
I'm surprised a 100-user site requires OSPF, EIGRP, RIP and BGP. If you removed that requirement, I would say hands down a Cisco Meraki MX. Something around the size of an MX85.
https://meraki.cisco.com/product/security-sd-wan/medium-branch/mx85/
It is cloud managed. You only need a web browser.
If the routing protocols are a hard requirement, then I would look at the Cisco Firepower 1000 series.
https://www.cisco.com/c/en/us/products/security/firepower-1000-series/index.html
ā08-03-2022 12:45 AM - edited ā08-03-2022 12:45 AM
What are your throughput requirements? Based on the requirements you have posted so far you could go for the FPR2110. I would not recommend getting the ASA as the Firepower devices are now slowly but surely replacing them.
ā08-03-2022 05:26 AM
Thanks everyone, throughput is around 1 G, and management wants a long-term solution, and it fits future expansion as well.
To ensure that the Firepower 2100 series supports site-to-site VPN, remote VPN access, and restrict some remote VPNs to access certain servers but not the whole network. Routing protocols in case we need them in the future, because they will have some remote branches of the company.
Or do you suggest another product to take instead of the Firepower 2100 series.
Thanks again
ā08-03-2022 05:46 AM
The 2100 series will give you everything that your requirements specify and will allow for future expansion. Again, depending on your future network plans, I would recommend considering the FPR2130 or FPR2140as this will give you an option to install a 10Gig SFP module if you at some point would require this.
ā08-03-2022 07:43 AM
Thanks so much @Marius Gunnerud
ā08-03-2022 07:53 AM
Please @Marius Gunnerud What would you recommend to buy FMC for management or other software.
Thanks
ā08-03-2022 08:31 AM
This depends on budget. Configuration support for FDM is getting better and with the integration with CDO it is quite good. I have mainly used FMC.
ā08-03-2022 07:55 AM
2100s are great IPS NGFW. Just make sure you get the requirement for the IPS throughput. You want to know how much ISP throughput you'll need. A 100 users is small network. EIGRP will be the easiest to use if you decide to connect multiple buildings together. When it comes to BGP this is a handoff provided by the service provider for multiple sites.
ā08-03-2022 08:24 AM
I'd be more aligned with @Philip D'Ath 's recommendation of a Meraki firewall for simplicity. For most smaller networks having the firewall simply default route RFC 1918 subnets to the inside generally suffices.
Otherwise if you really need all of those dynamic routing protocols, an 1100 series can scale up to several Gbps and be a better investment than the 2100 series which is getting quite old by now. Although I do wonder how you can possibly need EIGRP if you are running Microtik and Netgear now. Similarly BGP is seldom needed as it generally suffices to have a default gateway to your ISP router.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide