We are currently running the 515 in HA mode.  I love it!  I can run in turn
of the active PIX and the users don't even know about it.  Currently I have
about a thousand users going through this setup.  The one thing I would
recommend that we did not do up front as we were trying to "save a buck or
two" is using something like a 2912 on the outside and inside instead of
hubs, we have recently upgraded the units and did see a performance
increase.
A side note, we are having one problem with this setup and Cisco is working
with us on it, every once in a while a user will get locked up inside the
pix and we will have to do a "cl xlate local" command on the internal ip.
Just something to keep in the back of your mind in case it pops up.
Have fun
Jeff

Jeffrey R. Waters
Senior Systems Engineer
Information Technology, Hanover County


-----Original Message-----
From: John Shi [mailto:[EMAIL PROTECTED]]
Sent: Monday, September 17, 2001 12:51 AM
To: Exchange Discussions
Subject: What Pix firewall model would you use based on your experience?


Hi Everyone,
This is Out of Topic. We have less than 300 users in the company. I was
wondering what model of Pix firewall I should choose.

I have Pix 515 and 525 in mind. Does anyone have any experience on this?
I am $3000 short if I go with Pix 525. I would have $3000 left if I go
with Pix 515.

I would need a NIC card for DMZ. Pix has Strict and UN. What would you do
if you were me.

Thanks
JOhn Shi

_________________________________________________________________
List posting FAQ:       http://www.swinc.com/resource/exch_faq.htm
Archives:               http://www.swynk.com/sitesearch/search.asp
To unsubscribe:         mailto:[EMAIL PROTECTED]
Exchange List admin:    [EMAIL PROTECTED]

_________________________________________________________________
List posting FAQ:       http://www.swinc.com/resource/exch_faq.htm
Archives:               http://www.swynk.com/sitesearch/search.asp
To unsubscribe:         mailto:[EMAIL PROTECTED]
Exchange List admin:    [EMAIL PROTECTED]

Reply via email to