Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

VPN on router or PIX. Which is better?

I have not been able to find any concrete information regarding running VPN on a PIX firewall or 2620 router as to which one would perform better for VPN. We have a PIX 520 firewall and a Cisco 2620 router (neither one has the hardware acceleration card). Which one would be better for running site to site VPN? We will most likely only have around 10-20 site to site tunnels. Also, we are wondering if it would be better to terminate the VPN tunnel inside the PIX so that the unencrypted packets could then get inspected by the PIX? Or is it better to pass the encrypted traffic through the PIX and terminate the tunnel on the other side (the inside) on the 2620 router? Thanks for your help,



Re: VPN on router or PIX. Which is better?

If you are doing lan to lan hub and spoke, and intend for the spokes to communicate to one another as well, you need to use the router for vpn. The pix does not do redirect.

Putting the pix in from of the router is also good for security.