RE: QOS on PIX

From: Scott Morris (swm@emanon.com)
Date: Fri Mar 19 2004 - 10:49:03 GMT-3


This really isn't the proper forum for firewall debates as these have
nothing to do with the R&S exam. You may find more interesting responses
posting to a security forum, although I think that if you truly look at
things and have potentially implemented both series of firewalls, you'll
find that they are very close, and the PIX is better at some things while
the Netscreen is better at others.

There's really no way to make a bold, blanket statement that you have
without other people considering you simply "uninformed".

 
Scott Morris, CCIE4 (R&S/ISP-Dial/Security/Service Provider) #4713, CISSP,
JNCIS, et al.
IPExpert CCIE Program Manager
IPExpert Sr. Technical Instructor
swm@emanon.com/smorris@ipexpert.net
http://www.ipexpert.net
 
PS. As for QoS. What kinda support are you looking for? Your firewalls
should firewall, not be making preferential treatment decisions for your
network. "Support" is a vague word, and yes the PIX knows how to handle
different IP Prec/DSCP levels. But look at your net design anyway.

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of
Richard Dumoulin
Sent: Friday, March 19, 2004 2:45 AM
To: Tran Kim Phong; 'Ahmed Mustafa'; ccielab@groupstudy.com
Subject: RE: QOS on PIX

Then PIX is still far behind Netscreen !!

-----Mensaje original-----
De: Tran Kim Phong [mailto:tkphong@globaleis.com] Enviado el: viernes, 19 de
marzo de 2004 8:33
Para: 'Ahmed Mustafa'; ccielab@groupstudy.com
Asunto: RE: QOS on PIX

Hi Admed,
PIX doesn't support QoS. BTW, you can configure QoS at the gateway router.
Thanks,

Kim Phong.

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of
Ahmed Mustafa
Sent: Friday, March 19, 2004 10:04 AM
To: ccielab@groupstudy.com
Subject: QOS on PIX

What is the best way to configure rate-limiting on servers if they are
directly connected to PIX. Does PIX support QOS, if not then what is the
best way to confiures some media servers that are connectely directly on PIX
DMZ ports to prevent servers from chocking since other traffic such as ftp
file transfer, email and others are leaving the network at the same time.

Thanks,

Ahmed



This archive was generated by hypermail 2.1.4 : Thu Apr 01 2004 - 08:15:36 GMT-3