Community discussions

MikroTik App
micsupeti
刚刚加入了
Topic Author
Posts: 16
加入: Sun Feb 16, 2014 8:12 pm

Cisco ASA change to CCR1072

Tue Nov 21, 2017 12:33 pm

Dear Forum Users,

I would like to change my two Cisco ASA 5520 for two MikroTik CCR1072-1G-8S+. The Cisco ASA 5520 firewall throughput 450Mbps. This value is few. I'm looking for a device that knows the following:
- device redundancy ( High Availability / Failover )
- firewall throughput minimum 2-4Gbps
- management via VPN
- VLAN
- NAT
- SFP+ ports
- TCP / UDP connection limit management
- Serving about 1500 and 2000 users simultaneously to the internet

I was thinking of Mikrotik CCR1072 as a possible alternative. What do you think I can change my Cisco ASA5520 with Mikrotik CCR1072?



Thank you!
Top
Kindis
Member
Member
Posts: 422
加入: Tue Nov 01, 2011 6:54 pm
Location:Sweden

Re: Cisco ASA change to CCR1072

Tue Nov 21, 2017 10:56 pm

尽快思科防火墙和ccr is a router. Not the same type of product. ROS does have a firewall and can be used but is not built to be a firewall.
I use ROS at home as both firewall and router but would not do so at work.
I personally like Pfsense a lot. They also have some great appliances and can run in a hypervisor if needed.
Top
troffasky
Member
Member
Posts: 429
加入: Wed Mar 26, 2014 4:37 pm

Re: Cisco ASA change to CCR1072

Wed Nov 22, 2017 12:38 am

Dear Forum Users,

I would like to change my two Cisco ASA 5520 for two MikroTik CCR1072-1G-8S+. The Cisco ASA 5520 firewall throughput 450Mbps. This value is few. I'm looking for a device that knows the following:
- device redundancy ( High Availability / Failover )
Unfortunately there isn't native RouterOS mechanism for sharing state or config between multiple devices. If you can live with no state and manual config replication, you'll be fine...
Top
kujo
Member Candidate
Member Candidate
Posts: 169
加入: Sat Jun 18, 2016 10:17 am
Location:Ukraine
Contact:

Re: Cisco ASA change to CCR1072

Wed Nov 22, 2017 7:48 am

尽快思科防火墙和ccr is a router. Not the same type of product. ROS does have a firewall and can be used but is not built to be a firewall.
I use ROS at home as both firewall and router but would not do so at work.
I personally like Pfsense a lot. They also have some great appliances and can run in a hypervisor if needed.
My ccr1009 has a firewall rules count over 100, over 50 nat rules and mangle over 90 for queue and easy connections understanding.
Connections count over 8000. Max net load 300mb/s. Many vpn ipsec channels, capsman for over 150 users and 11 wifi caps, OSPF. Max cpu load 35%. What do you mean about this?


Yours respectfully!
Top
Kindis
Member
Member
Posts: 422
加入: Tue Nov 01, 2011 6:54 pm
Location:Sweden

Re: Cisco ASA change to CCR1072

Wed Nov 22, 2017 8:07 am

Cisco ASA is built to be a firewall with a lot of redundancy functions. You can cluster for HA and share states so a failover is more or less seamless for users.
You can use ROS as a firewall but it's not built for it and speed may suffer. It is my experience that adding a "firewall" rule to a router class device effects performance more then if it's a firewall class device.
As I said you can use ROS as a firewall, I do this myself, but if you want to replace a Cisco ASA with a CCR it should be pointed out that it's not the same type of device.
And also if he want HA Cisco ASA is better at this. So he cannot replace that out of the box.
Top
kujo
Member Candidate
Member Candidate
Posts: 169
加入: Sat Jun 18, 2016 10:17 am
Location:Ukraine
Contact:

Re: Cisco ASA change to CCR1072

Wed Nov 22, 2017 11:36 am

Yep... HA its also bgp, few isp... etc. Any device spend cpu to firewall rule processing! But mikrotik is not a security appliance with antivirus, thread detectors, etc...


Yours respectfully!
Top
micsupeti
刚刚加入了
Topic Author
Posts: 16
加入: Sun Feb 16, 2014 8:12 pm

Re: Cisco ASA change to CCR1072

Wed Nov 29, 2017 5:34 pm

Thank you your answare!
Top

Who is online

Users browsing this forum:Semrush [Bot]and 18 guests

Baidu
map