View Full Version : Linksys RV016 / Is it a firewall?
smartcard
03-06-07, 11:21 AM
Can I replace my PIX firewall with Linksys RV016?
Basically, I need to know if RV016 will do the firewall jobs same as or better than PIX?
YeOldeStonecat
03-06-07, 11:32 AM
I've replaced two PIX 501's with the RV016.....mostly because of the reason of VPN access. The 501 at one site was begging to crawl with too many users and VPN performance.
The early QuickVPN clients and firmware were a mixed bag. The PPTP VPN server has always been rock solid. The router itself is very solid. I've deployed several dozen of them already.....and I do find them very stable now...great at router to router VPN tunnels, great at PPTP VPN, and finally...been good with their IPSec QuickVPN client.
I have an RV082 at home that I usually use....gives me pretty much the same performance that any linux based router distro I've built has given me.
YeOldeStonecat
03-06-07, 11:37 AM
Adding to that...comparing the horsepower of each...
RV016 is 533MHz w/64 megs....200 megs router throughput and 90 megs 3DES VPN throughput.
PIX 501 is...I "think" 166MHz with 16 or 24 megs depending on version. I forget throughput...wanna say somewhere in the 30's for router throughput and 8 megs 3DES throughput....but I could be quite off there...I think EricD may see this post and have more accurate numbers.
As for "firewall" features....you can indeed build ACLs with the RV0 series. The PIX may indeed be more rich in this area....but honestly...how many PIX users out there run them much past default settings...which in actually it's just being used as a plain NAT router.
smartcard
03-06-07, 12:15 PM
I am trying to do the following at my office:
1) Install a RV016 2 or 3 ISP lines coming in to RV016 (load balancing is the goal)
2) Install the Enterprise (paid) box of the Endian ETM, that will do all the threat protections including virus, spam etc and the proxy for content filtering
3) Place my two Exchange servers behind the above two systems.
It will look like:
3 Internet lines (one ISP is giving real IP Eg: 212.143.143.129 which is used for pointing the mail server MX)
| | |
↓ ↓ ↓
LinkSys RV016
|
↓
Endian Firewall Mercury Pro
|
↓
Network Switch
|_ Exchange Server 1 (IP 192.168.0.10)
|
|_ Exchange Server 2
|
|_ Rest of internal network
Now my question is: There are two firewalls before my Exchange server, how should I instruct the SMTP traffic that is coming from the internet world to reach my local IP (IP 192.168.0.10) based Exchange server?
Is this a good solutions?
YeOldeStonecat
03-07-07, 01:20 PM
We did a fun experiment at a client..just to see if we could do it.
They had a business class DSL package...5x static IPs.
Netopia gateway (combo modem/router).
Switch
RV082 plus WAN NIC of server plus RED NIC of Endian router
Switch
LAN uplink of RV082 plus LAN NIC of server plus GREEN NIC of Endian router
The server ran ISA....its WAN NIC had a public IP mapped to it
The RED NIC of the Endian box had a public IP mapped to it..and their MX record pointed to that IP
The RV0 had a WAN port...public IP mapped to it, used for redundant back door for PPTP VPN.
So web traffic from the office went out ISA...
Mail was passed through the Endian box for virus and spam scrubbing...before it hit the Exchange server.
Fun setup!
vBulletin® v3.7.3, Copyright ©2000-2008, Jelsoft Enterprises Ltd.