Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Hub site device to terminate 100-200 VPN tunnels ?

I have a requirement to select a device to terminate between 100-200 VPN tunnels (approx 30 site-site, remaining client-site) with either CISCO 837 ADSL router or cisco VPN client at the remote end.

I need to be able to support these tunnels in the event of equipment failiure. I don't mind the client-sites having to re-establish a connection, but site-sites (837 router) must be up quickly also.

I am considering 2 options (but open to suggestions). I have been looking at the 3000 concentrators in various configs, but have also noticed the 515e router. It seems I could use a single 515e unrestricted and a 515e failover unit and support up to 2,000 tunnels (don't know what proportion are site-site). This seems a cheaper alternative to multiple 3005's or probably 2 3030's.

My question is what is the difference between these two options, I know the concentrator is a dedicated device but what is the difference in practice ? The concentrators appear to be the more expensive option - is it down to management, configuration, capacity, support for different clients ?

Any information would be gratefully recieved.

  • Other Security Subjects

Re: Hub site device to terminate 100-200 VPN tunnels ?


My advise would be to go with the 3030's. The question is will all your remote sites need to talk to each other? If so, the only way to do this with a PIX as the headend is to fully mesh all your routers with VPN's and after that there is no need for the PIX. The PIX will not allow traffic to enter an interface and leave the same.

The Concentrator will route between your remote sites like a champ if thats what you want. As far as equipment failure there really is no solution for LANtoLAN connections (not that I've found). VRRP is good but not as good as the Backup LAN to LAN feature when it comes to client to LAN connections.

Here is a couple links on Backup LANtoLAN..

Hope that helps.

New Member

Re: Hub site device to terminate 100-200 VPN tunnels ?

Thanks for your response. Point noted about routing between VPN sites. Any other issues anyone ?