Re: Spec'ing routers: 1721 vs 831



"Liz Eriksen" <NoSpam@xxxxxxxxx> wrote in message
news:Xns96C4595F14371elizabetheriksen2002@xxxxxxxxxxxxxxxxx
> Hello:
>
> I am trying to determine which routers to purchase for a small branch
> office deployment. Any suggestions very welcome.
>
> Basically, we have a central office with no more than 50 employees. We
then
> will have four branch offices with no more than 20 employees each. We want
> to connect evertying over a VPN.

it isnt so much the employee numbers as the WAN link speeds, traffic levels
and the number of connections to other sites that dictate the router.

The connections to the Internet would vary
> (DSL, ISDN, and T1) but would terminate on separate devices so that the
> Cisco router would only need Ethernet interfaces.

i prefer to have an interface in the router - esp. with interfaces that the
router may need to control like ISDN (where a mistake can generate lots of
calls and call charges).

generally, the routers you suggest are still available, but are old models
and likely to get phased out soon. use the newer ISR range - they have built
in encryption hardware.
www.cisco.com/go/isr

87x are the small ones (equiv to the 831, but faster).

if you want higher throughput then the 1801 has ADSL and 2 ethernets, but
there are others in the 180x range that may be better - note that you get
extra interfaces such as ADSL, but the box is cheaper than a more flexible
unit with only ethernet ports

assuming that the traffic pattern is star based, (unless you are planning to
use IP telephony between branches) then you need a bigger box at the central
site.

you need to pick the software options that give you support for the
encryption, firewalling etc you need - and since this can be 30% or more of
the cost you need to get it right.
>
> Will 831s work for this? Does a 1721 add anything to the mix?

831s may be enough for the small sites, but i would use 871.

1811 or 1812 or something bigger will be needed for the central site. the
box depends on the bandwidth
>
> Does anything change if the number of employees bumps up to 100 at central
> and the number of sites goes to 10?
>
> Finally, what if we also want to terminate roaming laptop client VPN
> connections as well?

you can do this on a router, but i prefer the VPN servers, since they are
easier to use with VPN clients, and minimising the client issues is what
makes a VPN less difficult.
>
> TIA
--
Regards

Stephen Hope - return address needs fewer xxs


.



Relevant Pages

  • Routing and VPN troubles...
    ... That is the essence of the firewalling / port filtering of the VPN - like ... can I trest the virtual VPN interfaces as normal interfaces for purposes of ... Consider FBSD 4 to be on dedicated ... All remote nodes have a "path" to the router, ...
    (freebsd-isp)
  • Routing and VPN troubles...
    ... That is the essence of the firewalling / port filtering of the VPN - like ... can I trest the virtual VPN interfaces as normal interfaces for purposes of ... Consider FBSD 4 to be on dedicated ... All remote nodes have a "path" to the router, ...
    (freebsd-net)
  • Routing and VPN troubles...
    ... There are about a 1000 different lists - hope this is the right one - if ... That is the essence of the firewalling / port filtering of the VPN - like ... can I trest the virtual VPN interfaces as normal interfaces for purposes of ... the router, not each other... ...
    (freebsd-net)
  • Re: HIPAA and firewalls
    ... >compliant manner using VPN. ... this is a bad and expensive method of purchasing a router. ... the VPN is setup in 5 steps. ... network IP block to both sides of the VPN tunnel. ...
    (comp.security.firewalls)
  • Re: WRT54GL with DD-WRT VPN firmware - wheres the beef?
    ... the easiest way to deal with a VPN is to *FIRST* understand how ... as the NAT LAN connected to the terminating VPN server, to the client. ... Destination router: ... Gateway IP = 192.168.3.1 ...
    (alt.internet.wireless)