cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
515
Views
0
Helpful
1
Replies

Do I really need two cascade firewall ?????

pinkheart
Level 1
Level 1

hello

I have a small ISP , and I have ISA2000 firewall now , I am intended to put Cisco PIX firewall , someone tell me that I should put two firewall the Pix then the ISA in cascade mode ( do I really need to do that ?)does the Cisco firewall enough for me.

The second question : which Pix is enough for me ( 501 , 506E or 515E)

I have about 500 internet users with 4Mbps dowonload and 512 Kbps upload) .

thanx in advance

1 Accepted Solution

Accepted Solutions

scoclayton
Level 7
Level 7

Based on the info provided here, I see no reason why you would need both a PIX and the ISA firewalls. The PIX should work fine by itself.

As for models of PIX to use, I would err on the side of getting something a little bigger than you may need right now. The 506E is enough horsepower for your current requirements but it is a 2 interface fixed chassis. If you think you will ever need another interface or more horsepower, you will probably be better off going with a 515E with a restricted license (restricted license for now as it can always be upgraded later). The 515E with the restricted license will allow you to add another interface to the PIX later on if you need to create a DMZ'ed network. The UR license on the 515E provides for more interfaces if needed.

Hope this helps.

Scott

View solution in original post

1 Reply 1

scoclayton
Level 7
Level 7

Based on the info provided here, I see no reason why you would need both a PIX and the ISA firewalls. The PIX should work fine by itself.

As for models of PIX to use, I would err on the side of getting something a little bigger than you may need right now. The 506E is enough horsepower for your current requirements but it is a 2 interface fixed chassis. If you think you will ever need another interface or more horsepower, you will probably be better off going with a 515E with a restricted license (restricted license for now as it can always be upgraded later). The 515E with the restricted license will allow you to add another interface to the PIX later on if you need to create a DMZ'ed network. The UR license on the 515E provides for more interfaces if needed.

Hope this helps.

Scott