cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1381
Views
0
Helpful
3
Replies

Should I buy ASA or use firewall Cisco CBAC?

news2010a
Level 3
Level 3

What is the real disadvantage of using Cisco IOS as the firewall when compared to spend money buying Cisco ASA?

In my case, I have outsourcing partners (semi-trusted network) and I need to make a decision on whether I should spend money buying a full Cisco ASA or firewall or whether using the Cisco IOS features is enough to keep my protection?

please opine.

1 Accepted Solution

Accepted Solutions

suschoud
Cisco Employee
Cisco Employee

The biggest disadvantage of using IOS f/w is the high load on cpu and memory usage of router.As router needs to keep a lot of tables in mem. for routing info,adding the translation tables to it can result in an unresponsive router.Ofcourse that depends on the traffic passing through this router.But with asa,you do not need to worry about that.Even the baby asa5505 can take care of large throughput.

Regards,

Sushil

View solution in original post

3 Replies 3

francisco_1
Level 7
Level 7

I would go for ASA instead. Better VPN/Firewall through-put. Its designed to protect networks whereas the router is primarily designed to route data If you want a filtering solution, use Cisco IOS. if you want a real firewall that does deep packet inspection, etc...use the Cisco ASA.

ASA's are Firewall/VPN Concentration/Router in a single box.

suschoud
Cisco Employee
Cisco Employee

The biggest disadvantage of using IOS f/w is the high load on cpu and memory usage of router.As router needs to keep a lot of tables in mem. for routing info,adding the translation tables to it can result in an unresponsive router.Ofcourse that depends on the traffic passing through this router.But with asa,you do not need to worry about that.Even the baby asa5505 can take care of large throughput.

Regards,

Sushil

Why not use Vyatta? It is open source and fully

supported. I use it as a firewall on an IBM

x3650 with dual quad-core processors with

4GB RAM. It pushes an insane amount of traffics. The configuration is very easy to

manage, very much like Juniper JunOS.

my 2c

Review Cisco Networking for a $25 gift card