Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
RabidFox
Jul 20, 2007

CrazyLittle posted:

3) ASA's are a pain in the butt to configure for QoS, and PIX 501's simply don't support it. 2621's aren't that great for NAT unless you get a good amount of RAM in them.
4) Your router should never be routing LOCAL traffic, so the port speed of the LAN interface shouldn't matter as long as you have a switch that's not pure poo poo on the inside.

These are the two most important facts. Slow lovely routers are terrible for vlan routing and acl's. If I had a nickel for every time I saw a 28XX or 26XX peg at %100 cpu time and stop responding because some dipshit thought it'd be a good "router on a stick" for vlan routing over fa speeds. FFS, it's a 200mhz proc. When the hardware based packet router gets overloaded it goes to the software based one, which blows balls, btw. I've gotten some very confused emails starting with, "well it worked XX months ago, what's different now?" "Have you added more users?" "uh, yeah"

moral of the story is, routing at fa speeds through a 2XXX series router with any sort of acl's/policy based routing is a NO!

Adbot
ADBOT LOVES YOU

RabidFox
Jul 20, 2007

jwh posted:

Aren't 2600 and 2800 series software CEF only? What hardware are you talking about?

oh balls, you're right. This was a cat 3XXX something, layer 3 switch, I had a 2XXX as a router on a stick with the same problem, ACL's with intervlan routing. The Cat was doing the same thing but it had policy based routing. NVM, then.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply