[c-nsp] Multi-homed ASA with a virtual interface for IPSec termination

Garrett Skjelstad garrett at skjelstad.org
Tue May 29 17:06:16 EDT 2018


I have a few hundred tunnels on some ASR1002X's no problem

MPLS over DMVPN

I, too, would hesitate to use an ASA/NGFW as an IPSec headend for S2S.

-Garrett

On Tue, May 29, 2018, 13:37 Gert Doering <gert at greenie.muc.de> wrote:

> Hi,
>
> On Tue, May 29, 2018 at 01:47:14PM +0100, Nick Hilliard wrote:
> > Juniper SRX handles this end of things a good deal better, imho.
>
> SRX seems to make a decent router, yes.
>
> Why they insist on calling it a "firewall" escapes me, though.
>
> gert
>
> --
> "If was one thing all people took for granted, was conviction that if you
>  feed honest figures into a computer, honest figures come out. Never
> doubted
>  it myself till I met a computer with a sense of humor."
>                              Robert A. Heinlein, The Moon is a Harsh
> Mistress
>
> Gert Doering - Munich, Germany
> gert at greenie.muc.de
> _______________________________________________
> cisco-nsp mailing list  cisco-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/
>


More information about the cisco-nsp mailing list