11-01-2017 10:40 AM - edited 03-08-2019 12:35 PM
Hi
We have a Juniper SRX firewal in our network that is only operating as a router and terminates two of our 1G point to point links. I would like to replace it with a Cisco router as all our routers are Cisco. What is a good replacement, I do have a spare 2921 that I can use.
11-01-2017 12:29 PM
Hi,
What model SRX is that? Depending on the number of interfaces you need 2921 probably will work. May I ask what is the reason for doing this? In general, Juniper firewalls have a lots of capabilities.
HTH
11-01-2017 02:01 PM
11-01-2017 03:09 PM
Hi,
Ok, that make sense. If you have a lot policies on the firewall, it may be a little challenging converting them to Cisco. If it is functioning as a basic layer-3 device than that should not be an issue. The 2921 will do the job.
HTH
11-01-2017 03:35 PM
11-01-2017 04:07 PM
Overall you may get better throughput with the SRX as it support 16 1Gig ports but if you just need a couple of Gig ports, the 2921 may work fine. Is the provider handing off a full 1Gig connection to you?
Try it with the 2921 and if you don't get the same performance level, you can bring back the Juniper.
HTH
11-01-2017 02:47 PM
Hello
If you sure you don't require any security/FW , UTM services etc Then a cisco 2921 ISR could be applicable for you - I guess it all depends on what you requirements -- review this
res
Paul
11-01-2017 06:26 PM
What is you actual traffic throughput at peak, i.e. interface to interface 600Mbps down x 300Mbps Up? A Cisco 2921 can only do approximately 250Mbps "aggregate throughput" - think 200 down x 50 Up Mbps. This is before turning on things like NAT, NBAR, FNF, or security. Cisco officially stopped updating it, but if you look hard you can still find archived copies of the router performance PDF. After 250Mbps you'd likely start to see the CPU stay beyond 75% utilization. That's when you start to creep up on packet delivery consistency issues, i.e. period of significant packet jitter.
11-01-2017 06:28 PM
What is you actual traffic throughput at peak, i.e. interface to interface 600Mbps down x 300Mbps Up? A Cisco 2921 can only do approximately 250Mbps "aggregate throughput" - think 200 down x 50 Up Mbps. This is before turning on things like NAT, NBAR, FNF, or security. Cisco officially stopped updating it, but if you look hard you can still find archived copies of the router performance PDF. After 250Mbps you'd likely start to see the CPU stay beyond 75% utilization. That's when you start to creep up on packet delivery consistency issues, i.e. period of significant packet jitter.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide