Hi Amey,
ASA/Pix can NOT terminate WAN connections such
as T-1, Frame Relay or MPLS to the firewall
itself. Pix/ASA can only terminate Ethernet,
Fast Ethernet and Gig connection to the
firewall.
If you go with Juniper/Netscreen or Nokia
appliances running Checkpoint, they can
terminate WAN connections to the firewalls
itself. I am not sure if it can terminate
MPLS connections.
Nokia, Juniper and Pix can be a DHCP Server.
Not sure about ASA.
Nokia/CP and Pix can not function as a proxy
server. Not sure about Juniper
Nokia/CP, Pix/ASA and Juniper can not function
as a AAA server.
If you are looking for an ALL in 1 solution,
I would suggest that you go with Linux
firewall. The linux can function as the
following:
AAA Server = Freeware Tacacs+ and FreeRadius (I have it running right now and it is working great)
proxy server = squid (i've it running right now)
firewall = ip masquerading with iptables (i've it running at the moment)
WAN routing = I've not tried but I think gen2
can do this. By that, I mean you can
terminate WAN connection such as T-1, Frame
relay to the linux box itself.
DHCP Server = dhcpd.conf will do the trick
As far as support for the linux firewall/
AAA/DHCP/WAN routing/Proxy, that's a separate
issue.
David