Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Brian A Seklecki (Mobile)
Date: Monday, November 5, 2007 - 12:26 pm

On Mon, 2007-11-05 at 07:23 +0100, Martin Toft wrote:

pf(4) has nothing to do with isakmpd(8), except as it relates to recent
addition of routing tags.

- PIX/ASA is going to get you a default packet "ASA" forwarding based on
interface weights 
- PIX/ASA is going to guarantee easily setup and functional Hybrid-XAUTH
VPN Road-warrior clients
- PIX has functional object-groups/group-object inheritance
- PIX/ASA has proprietary serial console fail-over (which is marginally
faster than waiting for CARP)
- PIX/ASA has some magical black-box inline transparent protocol
"fixups"
- PIX has a 4 hour SmartNet support contract option
- PIX/ASA has a SNMP MIB tree (Which we are working to catch up on)

I don't know about ASA, but the 5xx PIX doesn't support IPv6


Otherwise they're both software-based stateful IP packet forwarding
engines running on i386 with NAT and IPSec and 802.1q support.

OpenBSD will always scale better because you can run it on the harwdare platform of your choice.

~BAS

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
OpenBSD isakmpd and pf vs Cisco PIX or ASA, Chris Bullock, (Sun Nov 4, 5:09 pm)
Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA, Cabillot Julien, (Sun Nov 4, 5:29 pm)
Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA, Martin Toft, (Sun Nov 4, 11:23 pm)
Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA, Brian A Seklecki (Mo ..., (Mon Nov 5, 12:26 pm)
Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA, Chris Bullock, (Mon Nov 5, 5:14 pm)
Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA, Todd T. Fries, (Wed Nov 7, 5:09 pm)
Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA, Karsten McMinn, (Wed Nov 7, 5:50 pm)
Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA, Prabhu Gurumurthy, (Wed Nov 7, 6:34 pm)
Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA, Reyk Floeter, (Thu Apr 10, 3:27 am)
Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA, Claudio Jeker, (Thu Apr 10, 4:04 am)
Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA, Rod Whitworth, (Thu Apr 10, 4:29 am)
Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA, Matthew Dempsky, (Thu Apr 10, 12:52 pm)
Re: OpenBSD isakmpd and pf vs Cisco PIX or ASA, José Costa, (Fri Apr 11, 4:32 am)