Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

help design please

I need help with a network diagram. The company has 10 offices on the eastern sea-board of the US. 330 IT consultants.

IT dept provides web-enabled services to customers, employees, vendors and other stakeholders.Trying to get intp ASP ntegrator space. Plan is to start with 1 secured platform at the head office that clients can log into from anywhere using browser, Allied ASPs will be connected to system at head office thru extranet. Branch offices wil connect thru VPN.

Need to draw up network diagram with suggestions on hw.

I am new to this and do not know what I would need. Please help in any way.


Re: help design please

You should be looking for a Cisco VPN concentrator. Cisco has recently introduced SSL VPN support on their VPN Concentrator. Using SSL VPN, clients can connect to your corporate office using SSL VPN (from the web browser).

For Branch Offices, you can configure a site to site VPN on the VPN Concentrator. You would require either a PIX firewall, Router or VPN 3002 hardware client at the branch office.

New Member

Re: help design please

Thank you for your help. Would the diagram on work for me??

How would I go about deciding on which router and which of the PIX firewalls? Do you have any suggestions?

Re: help design please


Sorry for the late reponse.

The diagram in the above link, will work for you. Choice of router, firewall, etc depends on number of users, type of wan connection on the router, etc.

A PIX 515 would be a good choice for most medium sized enterprises. A VPN Conc 3005 is a good start but you might want to consider higher end VPN Conc models, if you plan to expand the number of remote sites, and remote users accessing your HQ via VPN.

What type of Internet connection do you plan to have at the HQ and Branch offices ? A 3600 or 3700 at the HQ would be a good start, enabling you to provide space for growth. A 1700 VPN accelerator bundle or a 2600 at the remote site would be a good choice for a site to site VPN. The choice of the router all depends again on the number of users at each site and the number of tunnels you plan to configure per site.

New Member

Re: help design please

How about an Extranet set-up?

New Member

Re: help design please

For the extranet, you could add another interface to the PIX box, and terminate the extranet connections on that interface.

CreatePlease to create content