07-17-2013 10:04 AM - edited 03-07-2019 02:27 PM
I have secondary Internet service dedicated for the most part to some wireless VLANs for guest and developer use. Right now a PIX is serving as the gateway and this works nice as I can DMZ the vlans and supply one-way inside access from our core to devices on the PIX DMZ vlans.
I am upgrading the link to a 300 Mbps metro ethernet link and need to replace the PIX. I can use an ASA, but I'm wondering if it's overkill for this situation. I know some access routers would work fine in this application, in fact, I've tested a 1941 which will do everything the PIX does now, but I know they lack the throughput to give me 300 Mbps wire speed. I thought a good L3 switch like a 3560 might suffice here, but I do minimally need nat for the outside connection and the VLANs behind the device need access back into the core for DHCP and DNS, plus, I do have to link it to my core to let hosts behind it communicate with devices on the wireless vlans.
Can anyone recommend a good solution for this? It doesn't have to be Cisco btw -- I'm agnostic here. Thanks in advance.
07-17-2013 11:08 AM
For the services you need, it requires a router.
Based on the bandwidth requirement, the 3925/3945 fits the bill.
07-17-2013 12:14 PM
Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
If NAT is required, I believe that will eliminate most small L3 switches, even the Metro versions.
Unfortunately, although 300 Mbps is trivial for most modern L3 switches, you'll need a higher end ISR to handle that much bandwidth.
Cisco recommendations:
350 Mbps - 3945E
250 Mbps - 3925E
150 Mbps - 3945
100 Mbps - 2925
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide