RadiclDreamer
Diamond Member
Looking to be able to block torrents, hopefully with my asa5520. Would a Cisco ASA AIP SSM-10 module do this pretty well? If so what are your experiences with them?
You do have the P2P option on?
p2p can use lot of ports so best bet is just block everything then open what is needed. That's fairly standard on corporate networks. Basically, you can connect to port 80, 443, maybe 22 and 21, and that's about it. It would not stop a torrent client to connect to a torrent "server" that is on port 80, but it would sure block a large portion of torrents.
I suppose there could be solutions that actually look at what the traffic is, but I imagine that would cause some latency to be analyzing every single packet like that.
A few things:
1. ASA5520 has reached EoX status.
Even though it'll be supported for another five years, my recommendation is to cut your loss, and invest in its replacement now.
2. If you choose to stick w/ Cisco, I'd go w/ their ASA 5585-X series, which are capable w/ L7 firewall capability. (they call it CX/context aware, but it's the same as Palo Alto, or other vendors' next-gen firewall)
Yes, you'll need to get the same service module for the standby unit.
A couple of thoughts:
The 5585-X is WAY overkill for what is being described here. A 5515-X will provide 350Mbps of CX (L7 firewall) throughput at like 1/20th the cost of a 5585-X with CX module. I won't read off all the specs, but they can be found here for all models:
http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/data_sheet_c78-701253.html
Since you appear to have some limited budget for hardware, I would really look into this new option since it should be about the same price as those SSM modules you are looking into. I agree with Cooky - It is a far better investment than those old modules.
Keep in mind this same box will do VPN, IPS, and botnet traffic filtering as well - licensing will apply, but in my experience they aren't all that expensive.
I dont really have a limited budget, its just needs to be planned. As this was a spur of the moment need, I'm trying to get by on the cheap