I've only raised this thread exactly because it is painful to me, that someone 
even considers only using sup720 for L2 Switching. If they have money to spend, 
they should spend it wisely, but... unfortunately, given what has been said 
here, IOS FW on sup720 is not a good choice, either because of lack of features 
comparing to PIX, or GUI management.

I wonder why Cisco is still supporting it on sup720, since marketing wise they 
are all about FWSM/ASA nowadays.

Personally, I'd put a sup32 with FWSM, but pre-sales people only consulted us 
technicians, after the order has been placed...

Thank you all for your input

Gustavo Novais

 


-----Original Message-----
From: Kevin Graham [mailto:[EMAIL PROTECTED] 
Sent: terça-feira, 5 de Junho de 2007 23:28
To: Gustavo Novais
Cc: Brian Stiff (bstiff); [email protected]
Subject: Re: [c-nsp] 6500 with IOS Firewall - Any experiences?

On 6/5/07, Gustavo Novais <[EMAIL PROTECTED]> wrote:

> I'll suggest him to continue using its current pix525 cluster,

If they want to give the IOS Firewall a shot though for what a
dual-720 is going to cost, putting in a pair of 2821 or 2851 SEC-K9
bundle's with SDM shouldn't be too painful.

> Do you know if the sup32-PISA brings any improvement on the IOS firewall area?

Given the additional CPU, performance would be helped, but you're
still stuck on a 6500 release train so it still going to suffer long
term. Keeping FW features up to date in 12.4T is hard enough (ie. I
don't believe current releases of any of the IM clients now are
compatible w/ the appfw IM code).
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to