[c-nsp] 6500 with IOS Firewall - Any experiences?

Kevin Graham mahargk at gmail.com
Tue Jun 5 18:27:36 EDT 2007


On 6/5/07, Gustavo Novais <gustavo.novais at novabase.pt> wrote:

> I'll suggest him to continue using its current pix525 cluster,

If they want to give the IOS Firewall a shot though for what a
dual-720 is going to cost, putting in a pair of 2821 or 2851 SEC-K9
bundle's with SDM shouldn't be too painful.

> Do you know if the sup32-PISA brings any improvement on the IOS firewall area?

Given the additional CPU, performance would be helped, but you're
still stuck on a 6500 release train so it still going to suffer long
term. Keeping FW features up to date in 12.4T is hard enough (ie. I
don't believe current releases of any of the IM clients now are
compatible w/ the appfw IM code).


More information about the cisco-nsp mailing list