
© 2007 Cisco Systems, Inc. All rights reserved. Cisco Confidential
28
ASR 1000: Zone-Policy Firewall
UWS-IPSEC1-2
Solution Benefits
Multi-Gigabit Cisco IOS FW in a router
Cisco IOS Firewall supported on all interfaces in the router
No service blades required
IOS ZPF uses CPL for:
L4, L7 (HTTP, IM, P2P…) Self, URL Filter,
DOS Params and more
Being able to scale Cisco IOS FW in a router
to multi-gigabit BW
Solution Objective
ALL FW processing is done within QFP up to 20Gbps
HTTP Max Setup: 200K
HTTP Max Connections: 2 Million @ 71% CPU
utilization
High-Speed Logging via NetFlow v9
WAN Aggregation Head-End
or Internet Gateway
Private Zone
GigE/10GigE/
POS/ATM/FR
Vlan 150
Vlan 160
IPsec
Zone
DMZ
Zone
Internet
Zone
Z-Pair Policy
18xx
38xx
HTTP
DNS
Keys to ASR 1000 (ESP20/RP1, IOS XE 2.2)
Comentarios a estos manuales