Zone Based Firewall on ISR Router

Unanswered Question
Jul 14th, 2009

I am contemplating deploying two ISR routers as zone based firewalls. They would have possibly up to four zones on them. I have both 2811s and 3845s and would prefer to use the 2811s as the 3845s have already been ear marked. Does anyone know what type of load this could put on a 2811? One interface and zone would be for an internet facing connection, one interface and zone for a user segment of about 150 people, the other two interfaces and zones would be to segregate specific server segments with no more then 15-20 hosts per segment. Thanks in advance.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Alex Yeung Tue, 07/14/2009 - 13:46


The IOS FW datasheet has performance numbers for different ISR platforms.

Also, in ISO FW Q&A:

Q. How much memory does Cisco IOS Firewall use?

A. Cisco IOS Firewall consumes roughly 700 bytes per connection for basic inspection. More detailed application inspection will consume more memory: for example, FTP, HTTP and VoIP AIC.

Hope this will give you some ideas.

Alex Yeung


This Discussion