[j-nsp] SSG 5 Load Balancing and NAT-PMP/uPNP questions

Jason Lixfeld jason at lixfeld.ca
Thu Sep 11 10:37:31 EDT 2008


I'm looking to possibly replace a PIX 515E with an SSG 5.  First off,  
does the SSG 5 support NAT-PMP or uPNP?  The PIX doesn't, but I'm  
hoping the SSG 5 does.  Next, I have this PIX at a colo with a bridged  
DSL circuit between it and my office which is a few kilometers away.   
At the office, the DSL circuit terminates on a Cisco 2651 via an ADSL  
WIC.  The 2651 defaults the traffic from my office LAN over the DSL  
link via OSPF to the colo where the PIX does all the natting,  
firewalling, etc.  All this works relatively well.  Now, I want to add  
a second DSL circuit.  My concern (and reason for the possible switch)  
is that I think the PIX will only do per-destination load balancing,  
so my goal of doubling up the bandwidth to make my all my warez and  
porn downloads twice as fast is a bit unrealistic in this  
configuration.  I'm hoping to use the SSG 5 to do what the PIX does  
(nat, firewall, etc from one network over two parallel paths) but do  
it with nice pretty per-packet load balancing.  If the SSG 5 does  
indeed do per-packet load balancing, that begets the next question -  
will the per-packet load balancing implementations between Cisco and  
Juniper play nice together or not.


More information about the juniper-nsp mailing list