07-07-2004 07:51 AM - edited 02-20-2020 11:29 PM
Hi All,
I am looking to get a small VPN for the office so two people who do travelling sales etc can work from wherever and I can work from home. My original idea was a Pix 501 but the presentation of ADSL is RJ11 and the PIX does not have any RJ45 ports.
Is there anyway around this?
If not then its a 1700 with a WIC-ADSL so it can act as a EasyVPN server for the 3 clients. But looking at the costs it seems cheaper to get a Dlink unit with ipsec support and then use the EasyVPN client on the desktops.
Thoughts and advice appreciated.
Kind regards
Phil
07-07-2004 10:34 AM
The telco is not providing any hardware? Ideally, you want a dsl modem that provides you ethernet out that you can plug into the outside interface of a pix
.
07-07-2004 11:05 AM
I have this setupin about 30offices right now and am happy with it. Iuse an external DSL modem and pluginto the outside interface. The PIX501willgive you the security you need over the D-link and is well worth the extera mony spent.You do get what you payforin this case, Ifsecurity is at allof concern, go with the 501 and not D-Link. The 501 uses the same operating systems and images as the other commercial based firewalls with some restrictions. This is high horsepower security for the money you spend.
To make it esier foryou clinets to connect, you would need a DSL service with a static IP assigned or the provider based DDNS of some sort if this exists. Ifthe IP address changed you would have to change the client everytime your IP changes.
The 501 support the new AES encryption and is in my opinion stronger than IPSEC and is the basis of the FIPS 140-2 standard for FEDERAL INFORMATION PROCESSING. Youcan readmore here.
http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf
Regards
James
07-08-2004 12:23 AM
Thanks James
So if I understand correctly I need an external DSL modem which takes an RJ11 in and presents out as ethernet and it should not try and use the dhcp assigned address from the provider itself but let the 501 grab the address.
Does the 501 support Dynamic DNS or will I have to go static?
Phil
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide