cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
799
Views
5
Helpful
8
Replies

Firewall Suggestion

jack samuel
Level 1
Level 1

Dears,

I want to know which model of Cisco ASA firewall I should suggest to customer, what inputs we should ask to customer so that we can size the firewall accordingly

thanks

1 Accepted Solution

Accepted Solutions

I would say that if you multiply the number of users by 100 you will have gauged the connections fairly accurately, and provided som wiggle room for each user.  Just to give an example, my computer is currently using 68 connections through my firewall at home.

But don't get too caught up in connections and throughput, at the end of the day it is the budget of the customer that will ultimately decide which ASA you will be suggesting.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

8 Replies 8

You could ask them some variation of the following:

  • number of users
  • their current internet bandwidth and any plans to upgrade that within the next 5 to 10 years
  • do they use site to site VPN and if yes how many do they currently have.  How many do they expect to have within the next 5 to 10 years
  • do they use remote access VPN, If yes, how many AnyConnect users do they have and how may do they expect to have in the next 5 to 10 years.  Do they use or want to use mobil devices with AnyConnect
  • Do they want or need URL filtering, IPS, Malware protection, etc.
  • Do they want or need high availability, Active/Standby, Active/Active, or clustered.

Then once you have your feedback research the different firewall models and then make your suggestions.  Don't exclude the 4100 / 9300 series FTD NGFW firewalls as this is the next up and coming product.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

Dear Marius,

I have understood all your points except no's of users and internet bandwidth

for example if a customer says he has 500 users and the internet bandwith is 34 mbps so how will u calculate throughput of firewall for decision.

thanks

You need the number of users as this will directly affect the AnyConnect license you will need to purchase if that is required, and this will indicate the number of connection that will be estabilished through the firewall (this will also be a deciding factor on which model you will recommend.)

As for the bandwidth, you would need to have access to monitoring equipment to see how much traffic is being sent / received to know what their current bandwidth needs are.  If they say that they intend to employ twice as many people over the next 5 years then you can safely say that in 5 years the used bandwidth will be dobble what it is today.  Of course this is not counting any webserver they may have and the amount of traffic that is generated towards them.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

Dear,

You need the number of users as this will directly affect the AnyConnect license you will need to purchase if that is required, and this will indicate the number of connection that will be established through the firewall (this will also be a deciding factor on which model you will recommend.)

lets keep all the VPN features aside and i want to decide the firewall based on 1000 users how i will judge how many connection will be from each user and on based of that  which throughput firewall has to be proposed.

thanks

the connections and throughput you will need to estimate based on what the clients current setup is using.  

To estimate throughput you would primarily gage this by the customer's internet bandwidth.  For example if the customer has a 1 Gb internet connection, it would not be a good choice to suggest an ASA that only has 250Mbps throughput.  So decide the throughput based on the current bandwidth and estimate the need for more bandwidth in the future (if needed).

again the number of connections throught the firewall needs to be estimated based on what the client currently is utilizing.  Normally the number of connections supported by a firewall that again supports the full internet bandwidth is sufficient but there can be some exceptions.  If you do not foresee a lot of connections from the internet and it is mainly the company employees that will be accessing the internet and DMZ and other local networks through the firewall you should be fine by just sizing up based on throughput / bandwidth.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

Dear Marius

Excellent hint for the internet firewall,

BUT FOR

DATACENTER FIREWALL:

again the number of connections throught the firewall needs to be estimated based on what the client currently is utilizing.

How I can know the utilization :

as u told me by monitoring software which will show me the interface,cpu,memory,xlate  utilization so based on that how I can estimate the firewall

And sometime it is a totally green network which is build from scratch then at that situation when we meet the customer they say that we have 1000 users in this situation how we can judge.

thanks

I would say that if you multiply the number of users by 100 you will have gauged the connections fairly accurately, and provided som wiggle room for each user.  Just to give an example, my computer is currently using 68 connections through my firewall at home.

But don't get too caught up in connections and throughput, at the end of the day it is the budget of the customer that will ultimately decide which ASA you will be suggesting.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

thanks for the precious time you used to reply the queries,

sorry for the late reply and ratings

Review Cisco Networking for a $25 gift card