Remote Access VPN options
 




IT Certification FAQ

 
|
Home
|
Microsoft
|
CISCO
|
CompTIA
|
Exam/Study FAQ
|
Employment FAQ
| Links  | Forums  |
Book Reviews


FAQFAQ  SearchSearch  MemberlistMemberlist  UsergroupsUsergroups  RegisterRegister  ProfileProfile  Log in to check your private messagesPrivate messages  Log inLog in

Remote Access VPN options

 
Post new topic   Reply to topic    Forum Index -> alt.certification.cisco
Author Message
Atif Sajid
Guest





PostPosted: Tue Jul 15, 2003 1:19 am    Post subject: Remote Access VPN options Reply with quote

Hello all,
my dialup users are experiencing very slow VPN connections when they connect
to our PIX 515E (multiple on different locations). VPN 3000 Concentrators
are very expensive and out of question. The other option that I have is to
get an unrestricted license and install VPN Accelerator in PIX 515.
However, at the same time I am thinking of buying 3600 routers to act as
perimeter equipment for our network edges. I can also use 3600 routers as
"Easy VPN Server" because those routers won't be doing any routing but just
sitting as gateway. Does anyone know what type of access-vpn performance
should I expect from these routers configured as Easy VPN Server. Can I
compare it to a 515E installed with VPN Accelerator cards. Any real-life
experiences or hints???
Thanks in advance.

Regards

Atif
Back to top
Walter Roberson
Guest





PostPosted: Tue Jul 15, 2003 2:12 am    Post subject: Re: Remote Access VPN options Reply with quote

In article <xfEQa.47$I4.8@nwrdny01.gnilink.net>,
Atif Sajid <atif.sajid@verizon.net> wrote:
:my dialup users are experiencing very slow VPN connections when they connect
:to our PIX 515E (multiple on different locations). VPN 3000 Concentrators
:are very expensive and out of question. The other option that I have is to
:get an unrestricted license and install VPN Accelerator in PIX 515.

What load figures are you seeing on the 515E's? How much traffic are
they carrying?

There is no point in spending money on a VPN+ card if the encryption
is not significantly loading your PIX.

In our experience, the single greatest cause of slow VPN traffic
is network latency. Have you tried putting a PC just outside your
515E and measuring the throughput you get then? When we did that,
we found that a PIX 501 <-> PIX 525 ran at pretty much the rated
maximum for the 501 -- much much faster than the same 501 appeared
to achieve when connected 1500 miles away. Latency, latency, latency!

--
I predict that you will not trust this prediction.
Back to top
RC
Guest





PostPosted: Tue Jul 15, 2003 9:17 pm    Post subject: Re: Remote Access VPN options Reply with quote

What are you using for the VPN client? Software clients can be slow,
depending on the encryption level, CPU speed, and RAM. And if you are using
Microsoft's make sure you uncheck the "Use Default Gateway on remote
network" unless you want ALL the users internet traffic going through the
PIX and back out.

How's the performance when only one user is connected? If it's still slow,
I'd be looking at the client, otherwise the PIX.

What's the CPU utilization on the PIX when the VPN is slow?

"Atif Sajid" <atif.sajid@verizon.net> wrote in message
news:xfEQa.47$I4.8@nwrdny01.gnilink.net...
Quote:
Hello all,
my dialup users are experiencing very slow VPN connections when they
connect
to our PIX 515E (multiple on different locations). VPN 3000
Concentrators
are very expensive and out of question. The other option that I have is
to
get an unrestricted license and install VPN Accelerator in PIX 515.
However, at the same time I am thinking of buying 3600 routers to act as
perimeter equipment for our network edges. I can also use 3600 routers as
"Easy VPN Server" because those routers won't be doing any routing but
just
sitting as gateway. Does anyone know what type of access-vpn performance
should I expect from these routers configured as Easy VPN Server. Can I
compare it to a 515E installed with VPN Accelerator cards. Any real-life
experiences or hints???
Thanks in advance.

Regards

Atif

Back to top
MysteryWife
Guest





PostPosted: Fri Jul 18, 2003 7:29 pm    Post subject: Re: Remote Access VPN options Reply with quote

Also remember...dial up users always experiance slow connections. That is
why it is called slow-speed internet! :-)

"Atif Sajid" <atif.sajid@verizon.net> wrote in message
news:xfEQa.47$I4.8@nwrdny01.gnilink.net...
Quote:
Hello all,
my dialup users are experiencing very slow VPN connections when they
connect
to our PIX 515E (multiple on different locations). VPN 3000
Concentrators
are very expensive and out of question. The other option that I have is
to
get an unrestricted license and install VPN Accelerator in PIX 515.
However, at the same time I am thinking of buying 3600 routers to act as
perimeter equipment for our network edges. I can also use 3600 routers as
"Easy VPN Server" because those routers won't be doing any routing but
just
sitting as gateway. Does anyone know what type of access-vpn performance
should I expect from these routers configured as Easy VPN Server. Can I
compare it to a 515E installed with VPN Accelerator cards. Any real-life
experiences or hints???
Thanks in advance.

Regards

Atif

Back to top
Jocelyn
Guest





PostPosted: Fri Jul 18, 2003 10:31 pm    Post subject: Re: Remote Access VPN options Reply with quote

Hi,

if you have a PIX-515E-UR it comes with a VPN accelerator and it can
handle more traffic/tunnel that a VPN3030 or a Cisco 3600.

Check your MTU size... and try connecting a PC just in front of the
PIX to see what kind of performance you get.

Hope this help
Jocelyn

"Atif Sajid" <atif.sajid@verizon.net> wrote in message news:<xfEQa.47$I4.8@nwrdny01.gnilink.net>...
Quote:
Hello all,
my dialup users are experiencing very slow VPN connections when they connect
to our PIX 515E (multiple on different locations). VPN 3000 Concentrators
are very expensive and out of question. The other option that I have is to
get an unrestricted license and install VPN Accelerator in PIX 515.
However, at the same time I am thinking of buying 3600 routers to act as
perimeter equipment for our network edges. I can also use 3600 routers as
"Easy VPN Server" because those routers won't be doing any routing but just
sitting as gateway. Does anyone know what type of access-vpn performance
should I expect from these routers configured as Easy VPN Server. Can I
compare it to a 515E installed with VPN Accelerator cards. Any real-life
experiences or hints???
Thanks in advance.

Regards

Atif
Back to top
Display posts from previous:   
Post new topic   Reply to topic    Forum Index -> alt.certification.cisco All times are GMT
Page 1 of 1

 

Copyright © 2002-2006 Web-S-Sense Pty. Ltd. All rights reserved.

Powered by phpBB
Advertising | Policies/Disclaimers | Contact us | Link to us


Featured Sites: Free Antivirus and Antispyware Info | Free PC Support | MCSE Directory