Compare cert salaries and plan your next career move
knwminus wrote: » Ok I am still shopping for a new edge router and I am trying to hash out between buying a cisco 2811 and building one with Zeroshell or PFsense. Can anyone confirm or deny that they have used the 2800 series (specifically the 2811) for an edge router. I am trying to keep our cost down and I am can pick one up for about 1000 bucks or so.
networker050184 wrote: » What do you need the router to do? We use them as customer CPE without issue.
networker050184 wrote: » Depending on the size of your internet pipe you should be good with a 2800. If you are just going to use some QoS and probably a default route you should be fine.
knwminus wrote: » Basically simply route. I would like to do some QoS as well along with the basics like security and such...for now I mean. Our User VPNS are going to terminate into our new Sonic wall boxes so our router won't need to do anything with that. We only have about 60 users. I guess I would need 3 physical ports (dmz, inside and outside) and the ability to one day add failover (Active/Active) and load balancing.
burbankmarc wrote: » If you look at my avatar that's a 2811 next to my left eye. But yeah I run the IPS on the router and I have a snort machine as well. Also on my snort machine I'm running Ntop which I would highly recommend.
burbankmarc wrote: » The more security the better. Also, to be honest I'm not real up on Cisco's IDS implementation so I mostly use the snort box. No slow down. The way I have it is 2811->3560->ASA->inside network. So on my 3560 I just setup a SPAN port and mirror all of the traffic into a promiscuous port on my snort box. The 3560 handles all traffic and you know how fast L3 switches are.
burbankmarc wrote: » No slow down. The way I have it is 2811->3560->ASA->inside network.
notgoing2fail wrote: » Do you think the SPAN port increases CPU utilization at all?
burbankmarc wrote: » I assume you mean switching from your existing equipment? Well as long as you configure everything properly it should be pretty quick. Just make sure you schedule down time though just in case.
knwminus wrote: » Yep its going to be put up or shut up time soon. I need to study the configs for our pix firewalls so I can make the cut over to our sonic walls boxes smooth as well.
notgoing2fail wrote: » You are having a great learning experience! This is why you chose this profession! What kind of sonicwall did you guys purchase? I have an old Pro 330!
knwminus wrote: » NSA 240. Its look pretty slickNetwork Security, Firewall & Wireless - NSA 240 Appliance Details - SonicWALL, Inc.
notgoing2fail wrote: » Wow that's pretty impressive.....makes my old Sonicwall look..well....old!!! I didn't know they change their design like that.....
Compare salaries for top cybersecurity certifications. Free download for TechExams community.