<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[H/W] Cisco pfSense Replacement? in Cisco</title>
<link>http://www.dslreports.com/forum/r20486491</link>
<description></description>
<language>en</language>
<pubDate>Sat, 06 Sep 2008 14:39:47 EDT</pubDate>
<lastBuildDate>Sat, 06 Sep 2008 14:39:47 EDT</lastBuildDate>

<item>
<title>Re: [H/W] Cisco pfSense Replacement?</title>
<link>http://www.dslreports.com/forum/remark,20512329</link>
<description><![CDATA[<A HREF="/useremail/u/843138"><b>MattE</b></A> : <div class="bquote"><small>said by  sporkme <A HREF="/useremail/u/168864"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  MattE <A HREF="/useremail/u/843138"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>Nowhere near the 10000 limit. I've never seen it higher than 800 states, with 2-4% CPU usage and like 4% memory.<br> </div>Something is amiss then if every client login causes 300 outbound connections and you don't peak over 800 states.  Just a handful of logins should bring you near the 10K default max - the state entries linger a bit.<br><br>It certainly wouldn't hurt to bump that up to 50K or so to see what happens while you wait on the new hardware.<br> </div>It actually happened again today. I'm talking with our developer now and it appears there is "retry logic" in the code that retries in a 5 batch loop, INDEFINITELY, if there is any sort of error. I think that is triggering the outbound issue.<br><br>I was on the FW when it happened today and the states were hovering around 450, then the firewall log went crazy blocking connections outbound to the same individual destination IP from 2 of our servers.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20512329</guid>
<pubDate>Tue, 20 May 2008 14:15:36 EDT</pubDate>
</item>

<item>
<title>Re: [H/W] Cisco pfSense Replacement?</title>
<link>http://www.dslreports.com/forum/remark,20512207</link>
<description><![CDATA[<A HREF="/useremail/u/168864"><b>sporkme</b></A> : <div class="bquote"><small>said by  MattE <A HREF="/useremail/u/843138"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Nowhere near the 10000 limit. I've never seen it higher than 800 states, with 2-4% CPU usage and like 4% memory.<br> </div>Something is amiss then if every client login causes 300 outbound connections and you don't peak over 800 states.  Just a handful of logins should bring you near the 10K default max - the state entries linger a bit.<br><br>It certainly wouldn't hurt to bump that up to 50K or so to see what happens while you wait on the new hardware.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20512207</guid>
<pubDate>Tue, 20 May 2008 13:57:00 EDT</pubDate>
</item>

<item>
<title>Re: [H/W] Cisco pfSense Replacement?</title>
<link>http://www.dslreports.com/forum/remark,20511348</link>
<description><![CDATA[<A HREF="/useremail/u/843138"><b>MattE</b></A> : I'm being told that the ASA doesn't support forwarding the correct protocols/ports to a MS RRAS server for IPSec/L2TP VPN capability. I am being told I HAVE to use the Cisco VPN client and the ASA as the client VPN endpoint.<br><br>Is this true?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20511348</guid>
<pubDate>Tue, 20 May 2008 11:20:15 EDT</pubDate>
</item>

<item>
<title>Re: [H/W] Cisco pfSense Replacement?</title>
<link>http://www.dslreports.com/forum/remark,20486743</link>
<description><![CDATA[<A HREF="/useremail/u/843138"><b>MattE</b></A> : <div class="bquote"><small>said by  sporkme <A HREF="/useremail/u/168864"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>While you're waiting on the replacement, bump up the state table and make sure you're running the latest 1.2 release.  (System->Advanced-Firewall Maximum States)<br><br>How many state entries are you peaking at now?<br> </div>Nowhere near the 10000 limit. I've never seen it higher than 800 states, with 2-4% CPU usage and like 4% memory.<br><br>And yep, this is the latest 1.2 release. It was just installed 2 months ago or so.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20486743</guid>
<pubDate>Thu, 15 May 2008 11:35:08 EDT</pubDate>
</item>

<item>
<title>Re: [H/W] Cisco pfSense Replacement?</title>
<link>http://www.dslreports.com/forum/remark,20486675</link>
<description><![CDATA[<A HREF="/useremail/u/168864"><b>sporkme</b></A> : While you're waiting on the replacement, bump up the state table and make sure you're running the latest 1.2 release.  (System->Advanced-Firewall Maximum States)<br><br>How many state entries are you peaking at now?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20486675</guid>
<pubDate>Thu, 15 May 2008 11:22:56 EDT</pubDate>
</item>

<item>
<title>Re: [H/W] Cisco pfSense Replacement?</title>
<link>http://www.dslreports.com/forum/remark,20486564</link>
<description><![CDATA[<A HREF="/useremail/u/843138"><b>MattE</b></A> : <div class="bquote"><small>said by  aryoba <A HREF="/useremail/u/676954"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>ASA 5510 firewall or 2811 router comes to mind ... :)<br> </div>I'm reading up on the ASA 5500 Series now actually. :)<br><br>Since we don't have any users behind the box and will use it as a firewall for our servers, do I need to worry about the number of users? What about the IPSec VPN peers?<br><br>&raquo;<A HREF="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd8048dba8.html" >www.cisco.com/en/US/prod/collate&middot;&middot;&middot;ba8.html</A><br><br>All of those seem to be in my price range. Do any of those include the AIP (&raquo;<A HREF="http://www.cisco.com/en/US/products/ps6825/index.html" >www.cisco.com/en/US/products/ps6&middot;&middot;&middot;dex.html</A>) module? I'm guessing no?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20486564</guid>
<pubDate>Thu, 15 May 2008 10:57:13 EDT</pubDate>
</item>

<item>
<title>Re: [H/W] Cisco pfSense Replacement?</title>
<link>http://www.dslreports.com/forum/remark,20486522</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : ASA 5510 firewall or 2811 router comes to mind ... :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20486522</guid>
<pubDate>Thu, 15 May 2008 10:52:06 EDT</pubDate>
</item>

<item>
<title>[H/W] Cisco pfSense Replacement?</title>
<link>http://www.dslreports.com/forum/remark,20486491</link>
<description><![CDATA[<A HREF="/useremail/u/843138"><b>MattE</b></A> : Hello all,<br><br>We're a growing ASP who hosts about 15 servers hanging off a 100Mbps connection in a data center. The servers range from Web Application Servers to an internal Exchange email server.<br><br>Right now, our main router/firewall/IDS is a dedicated IBM xSeries 306m running pfSense w/ Snort for IDS.<br><br>I'm am tired of "tweaking" this damn box and having to fix things that should Just Work&trade;. Snort is the major PITA right now, but I'm also having trouble with the firewall blocking outbound connections because we apparently generate more connections than an internal threshold allows, but no one can tell me what that threshold is. <i>(We do stock market transactions, so when a client logs into our app, we might generate anywhere from 100 to 300 outbound connection requests to our data provider, per login.)</i><br><br>We don't have a ton of money, but I'd like to move to a Cisco all-in-one box that will replace our pfSense box, be more reliable, and provide the following must-have features:<br><br><ul><br>&#8226; Transparent Firewalling</li><br>&#8226; Intrusion Detection System w/ Automatic Blocking</li><br>&#8226; IPSec VPN (Inbound to RRAS Server) Passthru Capability</li><br>&#8226; Web-based configuration management and reporting of IDS, firewall logs</li><br></ul><br><br>Does Cisco offer a product that can do this? Is the sticker shock going to make me spit my coffee on the screen? I could forgo the transparent firewall if 1:1 NAT is supported VERY well.<br><br>Thanks for any insight you can offer.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20486491</guid>
<pubDate>Thu, 15 May 2008 10:46:01 EDT</pubDate>
</item>

</channel>
</rss>
