VPN Network Design Question

Unanswered Question
Jul 20th, 2010
User Badges:

Hi Folks,

I have some doubts about designing a topology for VPN.

I have 2 6506-E Switches and three fiber optic rings for local branch offices. Each ring begins on one 6506-E Switch and ends into the other 6506-E Switch. I have ASAs 5505 in each brach office and now I have to design the network in order to encrypt the data between branch offices and the main one.

I don't have enough budget to adquire the module for VPNs.

I need to know the pros and cons of the following possibilities:

  • to adquire VPN concentrators in the main office
  • to establish the VPN with existing routers (with encryption module)
  • to establish the VPN with dedicated ASAs to concentrate them
  • another solution??

Thanks in advance for your help.



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Reza Sharifi Tue, 07/20/2010 - 18:54
User Badges:
  • Super Bronze, 10000 points or more
  • Cisco Designated VIP,

    2017 LAN


Since the 6500 do not do encryption by default, you would need to put a SPA-400 module in each 6500 and do encryption that way.  The other design would be to get small router at edge of each location (2900 or 3900 are good choices) and do the encryption between all small routers.  This way you you don't have to worry about touching the 6500.




This Discussion