Comparing Cisco VPN concentrator and a Cisco 2800 router with SDM

Hi!

I am thinking about buying something that will handle a lot of vpn tunnels and my cisco connection said that instead of bying a 3020 Concentrator I should buy a 2800 router with a vpn accelerator card. He said that it would be both cheaper and faster that the 3020. How do the

2800 router compare to the 3020 concentrator? Is it alot more difficult to administer? Any difference in licensing?

/Bq

Reply to
balroq
Loading thread data ...

In article , wrote: :I am thinking about buying something that will handle a lot of vpn :tunnels and my cisco connection said that instead of bying a 3020 :Concentrator I should buy a 2800 router with a vpn accelerator card.

Your Cisco connection is a bit off. The 2800 series all have built in hardware VPN accelaration, with no VPN accelerator card available.

:He :said that it would be both cheaper and faster that the 3020. How do the :2800 router compare to the 3020 concentrator?

The 2800 series vary a fair bit in performance.

formatting link
The range is from 90K pps to 220K pps (46 Mbps to 112 Mbps). These figures are considerably lower than some other figures I have seen for those models.

In a message about 7 months ago, I did a bit of performance analysis for the 2811:

formatting link
The figures came out in good agreement with the marketting of the

2811 as being suitable for dual T1's. The other 2800 series are also phrased in terms of small numbers of T1's.

The 3020 is rated to 50 Mbps encryption. 750 IPSec sessions (200 peers). The marketing positions it as suitable for up to a T3.

The 3030 has the same speed rating but support for more sessions. The 3020 is not upgradable to higher models; the 3030 is.

formatting link

As "50 Mbps" (3020) is not a very different number from "46 Mbps" (2801), it is difficult to tell where the truth lays. I have not seen pps figures for the 30x0 series.

What are your throughput and # of session requirements?

Reply to
Walter Roberson

The 2800 may work, but the 3000 series in general has a longer track record and has had more time to mature the administrative interface. If you are willing to tinker to save money, get the 2800. If you want it to hit the ground running, get the 3020. The 3020 is purpose built to the task, and the 2800 does a lot of other things.

The 3020 is a descendent of the Altiga acquistion, and the 2800 is an IOS based box. IOS VPN capabilities have come a long way, especially with the accelerator, and the web interface makes if friendlier than ever. Bottom line, though, is the 3000 has more field miles on it. I personally prefer the IOS boxes, but if the only task is VPN concentration, the 3020 is probably a better choice.

Reply to
Phillip Remaker

The 2800 series supports this VPN module AIM-VPN/EPII-PLUS Enhanced-performance DES, 3DES, AES, and compression VPN encryption AIM.

My cisco 2811 has one.

DT

Reply to
dt1649651

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.