Firewall Wizards mailing list archives
RE: Cisco 2621 opinions
From: Henry Sieff <hsieff () orthodon com>
Date: Sat, 13 Jul 2002 12:40:54 -0500
Joe: I have done this. They work pretty well, if you just need packet filtering. Using reflexive access lists, you can get session state for tcp (it just uses timeouts for udp). If you've worked with ipchains, the biggest change to remember is that first matching rule applies (not last). Capacity wise, I have used them on T1's without a problem. Good rule planning is essential. Logging is done via syslog (no real time) As for more advanced features, you can puchase the Firewall Feature set which gives you actual (basic) content inspection for well known protocols like http and smtp, and better tools for blocking DDOS and java, and the ability to set up real time alerting. The biggest problem I think would be that the 2600 series supports only telnet (and direct console) connects to the router itself, which makes remote admin a little sketchy; no ssh, which is a glaring oversite. But for your purposes, that may not matter. Learning curve would be negligible; not alot of gotchas, and the cisco web site has lots of documentation (although it can be hard to find.) Hope that helps; feel free to ask followups. Henry SIeff
-----Original Message----- From: joe macdonald [mailto:joe_macdonald25 () yahoo com] Sent: Saturday, July 13, 2002 10:20 AM To: firewall-wizards () nfr net Subject: [fw-wiz] Cisco 2621 opinions Hello all, I have a rather simple question that I would appreciate feedback on. I have a network of about 175 computers that I'm looking to put behind a Cisco 2621 router and also deploy it as a firewall. I'm new to the Cisco world, so I'm wondering how well these devices work as a router/firewall and how drastic the learning curve will be (I have deployed firewalls in the past using ipfw, iptables, ipchains on Unix systems). Also, my network isn't very big, but is the 2621 a suitable choice, or would a higher end model be necessary? Would a PIX be able to do this job better? (it's not exactly a comlpex routing situation, but is the PIX strickly a firewall?) Thanks. Any opinions are greatly appreciated. __________________________________________________ Do You Yahoo!? Yahoo! Autos - Get free new car price quotes http://autos.yahoo.com _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
_______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Cisco 2621 opinions joe macdonald (Jul 13)
- Re: Cisco 2621 opinions John Adams (Jul 13)
- Re: Cisco 2621 opinions Nick Drage (Jul 15)
- Re: Cisco 2621 opinions Charles W. Swiger (Jul 15)
- Re: Cisco 2621 opinions Patrick M. Hausen (Jul 16)
- Re: Cisco 2621 opinions Nick Drage (Jul 15)
- Re: Cisco 2621 opinions John Adams (Jul 13)
- Re: Cisco 2621 opinions Patrick Darden (Jul 15)
- <Possible follow-ups>
- RE: Cisco 2621 opinions Henry Sieff (Jul 13)
- RE: Cisco 2621 opinions Kent, Ashley (Jul 15)
- RE: Cisco 2621 opinions Brian Ford (Jul 15)
- RE: Cisco 2621 opinions Iannaccone, Al (Jul 15)
- Re: Cisco 2621 opinions Patrick Darden (Jul 15)
- Re: Cisco 2621 opinions Brian Ford (Jul 16)
- Re: Cisco 2621 opinions Patrick Darden (Jul 16)
- Re: Cisco 2621 opinions Carson Gaspar (Jul 16)
