Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Netscreen vs. Cisco ASA

Reply
Thread Tools

Netscreen vs. Cisco ASA

 
 
Andreas Heinzelmann
Guest
Posts: n/a
 
      08-30-2007
Hi there!

I just wanted to get some advice.

I have to set up 10 dial-up-VPNs (IPSec) to our corporate network. The
available Hardware Platform is a Juniper NS5GT with which I have no
experience at all.
On the other hand I could use a Cisco ASA Appliance (probably the 5505).

So could you please give me some pros and cons about the two systems? I
would really appreciate it.

Thanks....Andy

P.S. I have some Cisco experience (CCNA Level)



 
Reply With Quote
 
 
 
 
Lutz Donnerhacke
Guest
Posts: n/a
 
      08-30-2007
* Andreas Heinzelmann wrote:
> So could you please give me some pros and cons about the two systems? I
> would really appreciate it.


Choose the system you can work with. Your Cisco IOS experience is not that
helpful on ASA, but it might cut down the learning step.
 
Reply With Quote
 
 
 
 
drdisk@drdisk.de
Guest
Posts: n/a
 
      09-03-2007
Andreas Heinzelmann <(E-Mail Removed)> wrote:
> Hi there!
>
> I just wanted to get some advice.
>
> I have to set up 10 dial-up-VPNs (IPSec) to our corporate network. The
> available Hardware Platform is a Juniper NS5GT with which I have no
> experience at all.
> On the other hand I could use a Cisco ASA Appliance (probably the 5505)..


The 5GT might be just a bit too small for the task, since the standard
license only gives you 10 tunnels to work with. So if you plan to expand
on the number of tunnels in the near future you either need an extended
license for the box, or a bigger box with higher limits.

The 5GTs basically come in 3 flavors:

License Users Sessions Tunnels
10-user 10 2000 10
Plus unlim 2000 10
Extd. unlim 4000 25

("get license" on the cli will get you the license and limits on the box)

If you plan to do granular acls you might also hit the 5GT limit of 100
acls.

> So could you please give me some pros and cons about the two systems? I
> would really appreciate it.


Myself, I find the PIX syntax somewhat arcane and unintuitive. YMMV
though. The Netscreens are IMHO straight forward to configure. But as
Lutz wrote, use the box you can work with best _and_ that fits the
requirements.

> Thanks....Andy


Ciao Chris
--
All diese Momente werden verloren sein in der Zeit, so wie Tränen im Regen
Dipl-Ing (FH) Christian 'Dr. Disk' Hechelmann <(E-Mail Removed)> IRC: DrDisk
GPG Fingerprint: 53BF634B 28326F92 79651A15 F84ABB55 4F068E4E
Ich finde, scharfe Waffen und "Feuer nach eigenem Ermessen" sollte zum
Adminjob dazugehören. [Lars Marowsky-Bree in d.a.s.r]
 
Reply With Quote
 
Doug McIntyre
Guest
Posts: n/a
 
      09-04-2007
http://www.velocityreviews.com/forums/(E-Mail Removed) writes:
>Andreas Heinzelmann <(E-Mail Removed)> wrote:
>> Hi there!
>>=20
>> I just wanted to get some advice.
>>=20
>> I have to set up 10 dial-up-VPNs (IPSec) to our corporate network. The
>> available Hardware Platform is a Juniper NS5GT with which I have no
>> experience at all.
>> On the other hand I could use a Cisco ASA Appliance (probably the 5505)=

>.


>The 5GT might be just a bit too small for the task, since the standard
>license only gives you 10 tunnels to work with. So if you plan to expand
>on the number of tunnels in the near future you either need an extended
>license for the box, or a bigger box with higher limits.


FWIW: dialup VPNs don't usually use tunnels in Netscreen terminology.
The 10 tunnel limit is more along the lines of site-to-site VPNs.

I usually use up the limited session counts on the 5GT before anything else.

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
please please your help, VPN site to site between ASA and Netscreen ozoubi Cisco 0 09-23-2010 08:11 AM
ike phase 1 lifetime, asa with netscreen Bart Cisco 1 06-11-2009 11:25 AM
problems with cisco <-> netscreen scubabri@gmail.com Cisco 2 01-29-2008 05:13 PM
site-site VPN tunnel between cisco pix 515 E version 7.0(4) and netscreen. Dil Cisco 0 12-13-2007 10:54 PM
Netscreen-Remote client talking to Cisco VPN 3005? Road Rage Cisco 0 05-11-2005 03:26 PM



Advertisments