Which Cisco Firewall Is Suitable For Me
Oct 16, 2009i want a Cisco firewall suitable for one dedicated server protection, that server would host up to 30 vps
and i may buy another server in future, so what do you recommend?
i want a Cisco firewall suitable for one dedicated server protection, that server would host up to 30 vps
and i may buy another server in future, so what do you recommend?
Is a basic Cisco ASA 5505 suitable for a low-bandwidth colocation environment? I run a small virtualization network, going to be expanding to multiple hosts with a SAN and looking for something that is more secure and easier to manage.
Right now, I only have 12 virtual servers and I'm only pushing about 1-1.5mbps on average, though going to be expanding it so my capacity will be about 4x, including multiple physical servers and a layer2 switch. Sometimes managing it even now can become a PITA.
I would like to use an external firewall, but don't think I need something as hefty as an ASA 5510, as I doubt I'd max out the 5505 on throughput. I'm also sceptical about putting up a m0n0wall/pfSense box, as it might not be as cost effective to put it on new, reliable hardware, and putting it on some older/purchased off Ebay server could be unreliable as it is the entry point to my network.
Think the ASA 5505 would be a good entry level point?
We are looking to replace our existing WatchGuard Firebox's with a hopefully more reliable firewall from Cisco's range although I'm a bit lost when it comes to the different ranges.
Could somebody suggest a firewall that is capable of:
1: Both NAT & Drop-in (bridge) mode
2: Pretty low bandwidth requirements, no more than 10mbit/s traffic
3: SNMP Monitoring
4: High availability pairing
What is the difference between the Cisco PIX and Cisco ASA Firewall Systems?
Also which firewall do you guys recommend for a rack of servers
Does anyone know of a place or have for sale a Cisco PIX firewall? I have looked into ebay but was wondering what else is out there?
View 3 Replies View Relatedfrom where can i get the price of cisco firewall?
View 4 Replies View RelatedI already get a new firewall for my server cisco ASA and I don't know how to config it
is there any rules to get protection from shell and virus trojan as example
specifications and pricing of different CISCO PIX 515E firewalls?
View 2 Replies View RelatedDoes CISCO ASA Firewall block SQL and XSS Injection? If not, then which are the firewalls available which do this job. I have checked web application firewalls and found them to be too costly for my budget. What are the other cheap options available?
View 3 Replies View RelatedI have set up a Plesk Windows server behind a CISCO PIX 501 firewall and since then am not able to upgrade Plesk to the latest version. It cannot connect to the Plesk Update server. which port do I need to open and whether it will be inbound or outbound?
View 14 Replies View RelatedThought this might be of interest since the PIX vs. ASA devices are frequently discussed here ...
View 1 Replies View RelatedI am in the process of gathering the peices to move from a dedicated box to my own hardware in a local colo and am undecided how best to choose the edge device.
The colo has a 30Mb pipe with about 10Mb of it being constantly used during biz hours. Another 10Mb is being allocated in the next couple of months. I want to be able to burst to the full 30Mb when needed.
I am getting 12 IP's allocated but will increase to 24 soon if all goes well (fingers crossed!).
I will have for starters just a single Proliant running dnp on 2008 with IIS, FTP, Mail, ns1 and a 2003 VM running my secondary ns.
What I am unsure of is the edge device and looking for others that have used either a 2800 series router or a ASA5500 series firewall in a similiar fashion. I know what the raw throughput of each device is, but raw benchmarks are not realworld numbers by any means.
I am looking at the 2801 with IOS Firewall turned on and hopefully even some inspects for FTP and HTTP traffic. The other option and one that I am less familiar with is to use the ASA5505 instead which will do my basic routing but supposedly provide more thourough inspects and advanced rules.
Does anyone have experiance with either of these in a hosting environment and have input on the realistic throughput one can expect from either device?
There is a signifigant cost difference with the ASA5505 being much cheaper but I am more familiar with IOS. Would anyone recommend a 1841 router instead?
My host has helped me to install a switch. However, I don't know how to configure using the command line. Could anyone help me?
I need to be able to connect to my Cisco switch using Cisco Network Assistant. If you know the command sequence,
I'm planning on moving from a shared hosting environment to a VPS. I've got 2 VPS hosts in mind (FutureHosting and Zone.net), all of them offer cpanel, Plesk, and DirectAdmin.
My question to everyone is which cpanel would be more useful to me? I've used cpanel in the past, but I would like to try something new. With the VPS, I do plan to host people's websites and I would like to create more websites for myself and manage them. I am leaning more towards DirectAdmin since it has an option for creating small user panels for people. What does everyone else think?
Also, how do you determine how much RAM you need? I obviously can't monitor my own RAM usage since I come from a shared hosting environment? How will I know if I need 256, 384 or even 512MB of RAM? Should I just start off with 256 and go from there?
i want to rent bandwidth about 200M~300M from DC,
and i need a switch to handle the bandwidth.
on the core switch,
i want to cut different lan and limit each port's bandwidth,
two 50M,one 100M,and other are litle.
which switch can handle it?
my budget is not many,
i hope it is reliable,
i hear some good review about 3com and procruve,
but im not sure if they have good switch suit my purpose.
I wonder what component makes a mobo suitable for Linux?. Is it the chipset for the board or something else too?.
View 5 Replies View RelatedI am planning to use a VPS to create cPanel/WHM Reseller Plans for my customers. I have a question:
Is VPS really suitable to create Reseller Plans?
CPU load average is around 2-5% on my box. I'd like to know when I'll have to upgrade the CPU. Can I wait and add more accounts until it reaches 90%
View 12 Replies View RelatedI've always been a seller that's primarily used PayPal only.. However, on my next online venture, we're stepping it up a grade and will be implementing a full CMS system, an e-commerce cart module (or platform in its entirety) and security through SSL certification.
I've taken a look at the SSL certificates offered by eNom and was wondering what you all thought would be the cheapest certificate that is suitable and ready for e-commerce that will process credit cards, etc.
Certainly the more expensive, I can assume is more feature and security laden, but just wanted to know what you all feel is a good balance of price, security and readiness for e-commerce.
What is the suitable internet speed for dedicated server hosting about 30 VPS?
View 7 Replies View RelatedI have built a server so I can co-locate it to be used for shared hosting. The specification is high, compared to most dedicated server offerings, so I was considering splitting it up into different virtual machines for different purposes. The specification is: Intel Xeon 3230 (4x 2.66ghz), 8GB DDR ECC RAM, Seagate Cheetah SAS 15,000rpm (4x 147GB), Adaptec RAID 5405 (RAID 6 Array with Battery Backup), Dual on-board NIC, etc.
The original plan was to use this machine as just one linux server, but I am concerned most of its potential will not be exploited. So I am exploring the possibility of setting it up as 2 Virtual Machines, installing Linux on one and Windows on the other. This way I can offer hosting for ASP and ASP.NET, and possibly MS SQL and/or Exchange depending on costs for their licences.
What Microsoft licences are suitable for servers used for shared hosting? From what I can gather there are several ways of being licenced, but I can't figure out which is the most cost effective. It seems you buy the server OS edition that supports your requirements, then pay another licence per user (CAL?) - I haven't got a clue how many users I will need to have though. Then if you want to use MS SQL, DNS or Exchange you need the correct edition - and buy licences for these too.
Does anyone know roughly what I should be looking to pay for what? I would ideally like to have MS SQL, DNS and Exchange - but am aware that the licence could be so expensive that it wouldn't be worth doing.
Does anyone know of a hosting Linux package (must be UK based) that has the usuals (PHP, MySQL, subdomains, email, Apache ModRewrite) that is geared towards hosting lots of low bandwidth sites?
I use several great hosters but they limit the amount of addon domains or charge you through the roof for extra ones. I'm thinking a package that will let me do 15 - 25 domains. More would be a bonus. The bandwidth allowance is not a problem. A lot of my customers' sites use less than 100 MB a month.
I just applied yum updates and then attempted Plesk microupdates on a Mediatemple dv4 VPS running CentOS release 5.11.
I ran the 'up' alias (as I have done many times with success):
alias up='/usr/local/psa/admin/sbin/autoinstaller --select-product-id plesk --select-release-current --reinstall-patch --install-component base'
It halted with:
ERROR: Unable to install the "psa-updates-11.0.9-rhel5.build110140930.15.noarch" package.
The following could cause the installation failure:
1) psa-updates-11.0.9-rhel5.build110140930.15.noarch: No suitable solutions were found for the "sw-engine >= 2.5.2" dependency.
2) sw-engine-2.5.2-201409301549.rhel5.x86_64: No suitable solutions were found for the "libcurl.so.3()(64bit)" dependency.
Here are the RPMS updated just beforehand:
Updated:
bind.x86_64 30:9.3.6-25.P1.el5_11.2 bind-libs.x86_64 30:9.3.6-25.P1.el5_11.2
bind-utils.x86_64 30:9.3.6-25.P1.el5_11.2 kernel-headers.x86_64 0:2.6.18-400.1.1.el5
mysql.x86_64 0:5.5.41-1.el5.remi mysql-bench.x86_64 0:5.5.41-1.el5.remi
mysql-devel.x86_64 0:5.5.41-1.el5.remi mysql-libs.x86_64 0:5.5.41-1.el5.remi
mysql-server.x86_64 0:5.5.41-1.el5.remi nss.x86_64 0:3.16.2.3-1.el5_11
ntp.x86_64 0:4.2.2p1-18.el5.centos php.x86_64 0:5.4.36-1.el5.remi
[Code] .....
Do you recommend a software firewall when behind a hardware firewall?
All of our servers are behind Cisco ASA 5505 firewalls which we rent from Liquidweb. All are being managed correctly and setup to there optimal levels. With hardware firewalls firmly in place, do you still recommend a software firewall such as APF or IPTables (we're talking linux); in our opinion we see it as an extra administration overhead. If this is however untrue, we will change out thinking.
I've found a dedicated server at a great price and plan to stick with it, my first ( already have 2 vps accounts ). I don't have the money for a hardware firewall. However, I do have a chance to renew a Kerio WinRoute Firewall license from way back.
Does anyone think this would be better than the default windows 2003 firewall?
Anyone know anything about cisco pix 501s? i need help setting one up if anyone can give me a hand.
View 14 Replies View RelatedI just got a Cisco PIX 501 from my IT Guy for home use and he didn't reset the firewall to default settings so there are ton of old commands in here.
Is there a command I can use to reset the firewall back to the factory default settings?
Or is there anyway I can flash it back to factory default settings?
I am interested to buy a Cisco ASA firewall. So far I have never played with this gears and I wonder if it is easy to setup.
Is there any software provided by Cisco to setup rules and ACL thru some graphic interface software ?
I am on a tight budget for a Cisco firewall. I am browsing and seeing some affordable options in the x600 series.
Please tell me, which series is best?:
1600
2600
3600
The higher the better?..
Also what about submodels, like is 1650 better than 1600?
And how can I tell how much DRAM each one can take up to?
I see a lot of DDos related articles here at WHT. We've got hit multiple times by DDos and had to handle those attacks everytime with a different approach.
The largest one and the most well know one (we were in Times Mag, AP news, CNN, slashdot, you name it - just do a search about us on WHT) was Russian botnet cyberattack - we had to anaylyze netflow and then block everything on our edge routers, then on the firewall and then locally on the servers.
Since then we had number of other attacks, some of them we were not able to defend on the server level, while, as you can understand we can't do netwflow and manual intervention evey time somebody gets an attach.
We have very good scripts which allow to mitigate huge number of DDos attack, whet our scripts are finding attacking IPs and blocking them automatically - still some attacks could be blocked only on the router level.
I've read that Cisco Guard (I am interesed in 65xx version of it) suppose to mitigate DDos attacks in automatic mode.
after months of disruption moving servers into a new data centre, our once reliable colocation company has now had nearly 6 hours downtime in the last 16 hours. So much for network redundancy.
View 5 Replies View Related