Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfSense suitable replacement for Cisco 3005 Concentrator?

    Scheduled Pinned Locked Moved Hardware
    3 Posts 3 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      ttblum
      last edited by

      Hello,

      I am looking to replace an ailing Cisco 3005 Concentrator.  I have a Netgate m1n1wall 2D13 (http://store.netgate.com/-P219C83.aspx) running pfSense for testing, would that make be a suitable replacement for it?  Does pfSense have a granular traffic filtering setup as good or better than the Cisco 3000's interface?  Would the Netgate m1n1wall have enough horsepower for 50 IPSEC 3DES tunnels?  I'm looking for an embedded hardware device, can anyone recommend what a suitable replacement might be to replace a Cisco 3000 Concentrator?

      Thanks,

      Todd

      1 Reply Last reply Reply Quote 0
      • W Offline
        wallabybob
        last edited by

        It would probably be useful to also tell us the data rate you are expecting to see over those tunnels and whether the data is predominantly large packets or small packets

        1 Reply Last reply Reply Quote 0
        • jimpJ Offline
          jimp Rebel Alliance Developer Netgate
          last edited by

          As wallabybob implied, the data rate is more important than the number of tunnels. The ALIX 2D13 on its own can only handle about 18-20Mbit or so of IPsec, and that's with Rijndael (AES 128). With 3DES it's only about 8.

          You can filter IPsec however you like, so that shouldn't be a problem.

          pfSense 2.0 beta would probably be a better start for that kind of task instead of 1.2.3, primarily due to the improved IPsec GUI and the ability to have multiple phase 2 definitions per IPsec tunnel.

          Bonus for the switch: You can use OpenVPN instead of being stuck with only IPsec.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.