Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Will a 7206VXR NPE-225 work if I.... 1

Status
Not open for further replies.

IllegalOperation

Technical User
Jan 27, 2003
206
US
Hello everyone. Here is my scenario...

First, we have our main office. We also have seven remote apartment complexes we will be providing internet access to. I am going to tie each remote apartment complex to our main office using point to point DS1 circuits. At our main office, we will have a dedicated circuit (most likely a fractional DS3) to carry all these users out to the internet.

My question is, would a single 7206VXR NPE-225 be able to handle the stress of 7 point to point DS1 circuits along with a fractional DIA DS3? To go into greater details, I am planning on putting a pretty hefty access list on this router for security purposes. I am also going to GRE tunnel out to each remote site. I might use other CPU intensive features, such as NAT on this router.

Lastly, if I hook up a packet sniffer (or other security devices) to an ethernet interface on this 7206 - is there a way I can get it to inspect EVERY packet that passes through the router?

Your opinions are appreciated....
 
That 7206VXR is more router than you need...so to answer that question...YES, it will handle all those connections and your access-lists and then some.

If your running point to point circuits which I'm assuming you'll be using FRAME-RELAY, then why the GRE? You'll want to use NAT going to the ISP on the 7206VXR.

Yes, you can have a sniffer monitor all the traffic, you'll have to have it monitor the link to the ISP and not to the branch offices. You'll have issues with Source addresses and where the packets are coming from, but other than that, you can do what you want to do.

"I can picture a world without war. A world without hate. A world without fear. And I can picture us attacking that world, because they'd never expect it."
- Jack Handey, Deep Thoughts
 
Thanks IPKONFIG. Now when you say a 7206VXR is more than enough, are we talking about the NPE-225? I think something like a NPE-400 will be way too much overkill.

As far as the GRE goes, I am going to have a private subnet at each remote apartment complex. The routers at each remote complex will each be assigned a public address, and will take care of the NAT themselves. Unfortunately, I have servers at our main office that all of these remote private subnets need to communicate with. Hence forth the GRE.

As far as the traffic monitor goes, I will have issues with the source addresses? That hurts, because that is pretty much critical to what I am trying to do. IPKONFIG, can you email me at ctown22@hotmail.com? I would like to get more in depth with sniffing ideas. Thanks
 
I'll e-mail you this morning...have to square things away at work first. I won't forget about you.

"I can picture a world without war. A world without hate. A world without fear. And I can picture us attacking that world, because they'd never expect it."
- Jack Handey, Deep Thoughts
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top