• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

firewall user limits. please explain

cyr0n_k0r

Supreme [H]ardness
Joined
Mar 30, 2001
Messages
5,360
We are looking into getting a cisco pix firewall for a new office we are moving into.
Our current firewall consists of a dual wan router/firewall from hotbrick which I have loved.

However, we see the need for a more advanced solution that is a little more geared towards enterprise. I have been looking at cisco pix and netscreen's on ebay and they all seem to have "user limits"

What is the user limit? We don't plan to use VPN but we will have dozens if not hundreds of simultaneous connections over non standard ports for the traffic we will be pushing and pulling down.

Will these "user limits" limit the amount of connections the firewall will allow through it at any given time?
 
the user limits, refers to the amount of unique ip's that are either protected in the DMZ or on the internal segment of the network.

The # of connections per IP would only be really limited by the appliance. I think for less than 25 people, the pix or netscreen's should be fine.

Don't know what your budget is... but the ASA are a steal for their cost. We bought some big 5520 and had me ordered some 5505, and to be honest they rock. In my book, they are only 2nd to Checkpoint.

(let me qualify my fw experience... raptor, isa, checkpoint, and now asa.)
 
I played with a raptor a few years ago. I liked it, but couldn't ever get it to allow ftp connections. It was a pain in the ass.

Our budget is only a few hundred dollars.

I'm really looking heavily at the pix 515 as it seems to be the cheapest rackmount pix that I can find.

We are getting about 13-16 public IP's, so I would need at least a 20 "user" license I assume correct?

I always thought the user limits were how many VPN connections were allowed.
 
on the PIX, i think be default you get as many VPN connections as your device can handle.
The user license count refers to the devices that the FW is protecting..

What are the 13 or 16 IP's going to do? the # of outside devices is irrelevant... whats more iimportant is how many devices you are protecting behind the pix.

Here is the exact link to the cisco licensing model for the pix.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_data_sheet09186a00800b0d85.html

BTW, don't know if you want to go with a pix 515... that would be two generations behind ( i am guessing... it would still run 6.x code). If possible, maybe get the 515E.
 
yes, I meant the 515e.

Number of devices protected behind the firewall? That would be 3 servers, moving to no more than 5 within the next year.
 
scratch that, it doesnt look like we will be able to afford the 515e.
Will the 515 even though its a few generations behind still serve it's purpose?

We will only be pushing about 30mbps through it with a few hundred connections over non standard ports.

We will not be running web services, email, ftp, or any of that sort.
 
The 515's are all compatible with 7.x code. I've been looking a them lately too as part of a budget VOIP project I'm working on. There' quite a few network refurbisher companies out there that'll do a 515 w/ 7.x code on it for under $900.

In my situation, I'm looking at it to also be the hub in a 13 spoke VPN WAN as well as QOS for SIP trunks. Have a 506E right now running that duty, but no QOS support, hence the replacement.
 
scratch that, it doesnt look like we will be able to afford the 515e.
Will the 515 even though its a few generations behind still serve it's purpose?

We will only be pushing about 30mbps through it with a few hundred connections over non standard ports.

We will not be running web services, email, ftp, or any of that sort.

The ASA 5510 is the replacement for the PIX 515E. The ASA's the same code as the PIXes, are faster than the 515E, cheaper and more features.
 
The ASA 5510 is the replacement for the PIX 515E. The ASA's the same code as the PIXes, are faster than the 515E, cheaper and more features.
the cheapest ebay has the asa 5510 is $2000.

I wouldn't call that cheaper. Maybe cheaper if you have thousands of dollars to spend and might save a few hundred buying a new 5510 over buying a new 515e.
 
one of my networks has a PIX515e running on it, with unlimited licensing ;-)


It had no issue connecting up with our DS3 (Foundry equipment for the fiber->cat5/copper), handles traffic with 6 or 7 public IPs. Behind it we have about 150 computers, a few webservers and our mail server.
It also was the end point for two remote office vpn tunnels.
It is a generation or two behind, but it is not yet ancient :D
 
Back
Top