Re: Scaling IPSec VPNs and Meshes ?

From: Dmitri Kalintsev (dek@hades.uz)
Date: Wed May 23 2001 - 18:37:37 EDT


On Wed, May 23, 2001 at 09:40:49AM +0200, Mati Gil wrote:
> We are testing this nice PIX GUI (I guess you're talking about PDM) but
> we're getting lots of unexpected results (bugs?) working with IPSec.
> I would better recommend installing VPN 3000 concentrators (3005 is cheap
> and supports till 100 LAN-to-LAN tunnels), they are really easy to
> configure. If your network is partial mesh, you can install VPN3002 in sites
> where they are acting as 'clients' of a VPN 3000 conecentrator.

Just don't buy into VPN5000 series, especially if you need features of v6.x
code for it. There's one under my desk right now, getting ready to be sent
back to Cisco after 2 months of fighting problems with it and having at
least one TAC case open and two "workaround provided" closed on it, and in
no way I'm ready to deploy something THIS unstable into production network.

---end quoted text---

SY,

-- 
 CCNP, CCDP (R&S)                          Dmitri E. Kalintsev
 CDPlayer@irc               Network Architect @ connect.com.au
 dek @ connect.com.au     phone: +61 39 674 3913 fax: 251 3666
 http://-UNAVAIL-         UIN:7150410    cell: +61 41 335 1634



This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:12:38 EDT