
how-to block ads
|
  Wannabee
@comcast.net
| [H/W] Will a Cisco 5505 meet my requirements?
I am new to Cisco equipment. Can anyone experienced with the ASA 5505 tell me if the router would meet my requirements, and if so, which SKUs?
I need 3 interfaces- Interface 0: Internet Interface 1: Office wired LAN Interface 2: Office WiFi LAN
For 1 -> 0, easy. We have a cablemodem, so DHCP client and NAT on 0, firewalled.
I need VPN inbound 0 -> 1, and I understand the 5505 does this, and you buy licenses to cover the maximum connections.
The wireless interface is the fun part- Interface 2 has no access to 0 or 1, except for pinhole access to the internet (interface 0) mapped by source MAC, destination site names, and ports (I have fixed role devices on WiFi).
Interface 2 must also allow VPN access to the office wired LAN (interface 1), and internet access as if in that LAN (for laptop users). That means VPN traversing 0->1 and 2->1+0. This is the requirement I am sketchy on.
So, is 5505 my router or not? I understand the base SKU allows only 3 interfaces, and is very restrictive about configurations, so I would need the SEC package.
Thanks for any help! | |   macyh Ex-Isp Premium,MVM join:2001-04-24 Medina, OH
·Armstrong Zoom In..
| Based on your specs, you'll want to configure the wireless interface as a DMZ. Remember that the ASA handles such configurations using separated VLANs.
You'll need the base ASA5505 plus the DMZ VLAN option. ASA's come setup for 10 or 50 or unlimited LAN connections. Depending on the number of users in your LAN, you may need to get the larger user license version, as well. If you need VPN services, that's also an add'l option item. (Hint: There are bundled ASA5505 packs that combine most of these options into a single SKU plus you save a couple bucks.)
Don't have the Cisco model nunbers handy, but any halfway decent Cisco ASA trained salesperson will be able to assist. Given this info, you can probably pick up the numbers off the CDW site (or any other qualified retailer online Cisco catalog, for that matter).
Disclaimer: I'm a bit rusty at Cisco sales config details, I'm sure there are others here with more detailed info, but I thought you deserved a prompt follow up. -- Macy Hallock, Medina, OH and Lutz, FL Ex-telco tech, network engineer and former ISP Owner | |
|