Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

NAT handling capacity of ASA5550 and 2821 router

Hi all,

I would like to know your thoughts on which device handles NAT better when used with IPSec tunnel: A Cisco ASA 5550 (Premium VPN lisense) and Cisco 2821 router.

The idea is: we want to connect the two different datacenters and I was wondering if we can actually do one to one static NAT for the whole subnets used on both sides. That would be /16 subnet pool for which we will do the one to one NAT. I do have dynamic NAT in mind too (overload), but in that case, we will lose the actual IP to be seen of one side at the other side.

Thanks in advance..



Re: NAT handling capacity of ASA5550 and 2821 router

Hi Gaurav.

With the router for statics you have to specify each ip address. if you do it via a dynamic pool, then you can't initiate a connection from the other side until the local side initiates and allocates a NAT entry.

however with an asa, with a simple static statement you can tell the ASA to do one to one mapping for the whole subnet, and this will allow traffic to be initiated from both ends. also performance wise, your asa5550 can handle a lot more vpn throughput than the 2821.