[c-nsp] ASA or FRSW in transparent mode over qinq

Christian Koch christian at broknrobot.com
Wed Jul 9 17:39:35 EDT 2008


im a bit confused by your use of terms in the question...

are you asking about vrf-aware firewalls?

or are you just unsure of the method a SP delivers layer 3 vpns?






On Wed, Jul 9, 2008 at 4:31 AM, Benny Amorsen
<benny+usenet at amorsen.dk<benny%2Busenet at amorsen.dk>>
wrote:

> "Pavel Skovajsa" <pavel.skovajsa at gmail.com> writes:
>
> > does anybody know whether ASA or FWSW is able to firewall qinq packets
> > in transparent mode? Does anybody have some configs of this?
> > In short we are a service provider who wants to offer firewall
> > protection to various customer qinq tunnels.
>
> I don't know the answer to your question, but I do have another one...
>
> Which firewall does MPLS providers use to connect customer VRF's to
> the Internet? 6500's with FWSM's? What if they have thousands of
> VRF's?
>
> All of the usual enterprise firewalls like ASA, Netscreen, Checkpoint
> VSX top out at a few hundred virtual firewalls per box.
>
>
> /Benny
>
>
> _______________________________________________
> cisco-nsp mailing list  cisco-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/
>



-- 
^christian$


More information about the cisco-nsp mailing list