cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1229
Views
0
Helpful
20
Replies

PIX 525 Multiple Outside Interface

Hi all ,

We are in the process of adding second isp for webhosting purposes .Is there any issue if we are making outside 2 interface on the pix .i need to host some websites through this new link ie isp2 .i had seen lot of suggestions in the forums .I need to confirm and ask some valuable doubts on the suggestions .

PIX Version 7.0(7)

20 Replies 20

You can grab the output of "show conn" during peak hours (once every 15 minutes) to check what is the maximum connections, but from the above output, it seems that the maximum connections does not exceed 30,000 connections.

You should be able to replace PIX525 with ASA5525-X, and still get a better specification than the existing PIX525.

Here is the datasheet for PIX525:

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5709/ps2030/ps2118/product_data_sheet09186a0080091b09.html

and you can compare it with the ASA5525-X from the above advised URL.

Oh, do you have a requirement for VPN, as PIX525 supports 2000 IPSec VPN tunnels, but ASA5525-X only supports 750 IPsec VPN (but it also supports AnyConnect SSL VPN, and IPS)

Hi halim ,

Thank you for giving me the continous support .

I have a separate box for vpn connectivity .But it is pix 515e.Once i replaced the pix 525 with a new model .I can use the pix 525  for vpn purposes .So the vpn  issue can solve . But my issue is about the throughput of new firewall. I will summarize the peak utilzation of the pix interfaces .

Interface Name         In                   Out

Interface1                   55 Mbps         10 Mbps

Interface2                  12 Mbps           20 Mbps

Intreface3                  80 Mbps          35 Mbps

Intreface4                  18  Mbps         70 Mbps

Intreface5                  350 kbps          400 kbps

Intreface6                  400 kbps          3 Mbps

Interface7failover        0                     3.5 Mbps

Do u have any suggestion for the throughput for my new asa .

With that throughput, I would suggest the ASA5525-X as that supports maximum of 600 Mbps, which is more than enough for your current throughput utilization.

Hi jennifer,

       Thank you for the update The data sheet firewall throughput is showing  2 Gbps . Firewall + IPS Services is 600 Mbps. That a good choice .Is there any issue if we using the ips with firewall .You have any link how we can use ips features in asa x series .

Here we go, the configuration guide for IPS feature on the ASA-X series:

http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/modules_ips.html#wp1266836

Hi jennifer,

         Any update on the suggestion .

Review Cisco Networking products for a $25 gift card