//flex table opened by JP

Click to See Complete Forum and Search --> : encryption speeds


vass0922
07-13-2001, 12:56 PM
We have a VPN running over a pair of PIX 520 firewalls, with a Cisco 3640
Router running
3DES encryption on each side of the VPN.

Basically

|3640 for 3DES encrypt | PIX Firewall/VPN | 100 mbps connection to
destination | PIX Firewall/VPN | 3640 for 3DES Encrypt |


This solution only gives us 18Mbps data transfer rates, so we're wasting a
100 Mbps line.

Is there another solution that allows us a faster transfer rate WITHOUT
losing the encryption type and level.

I've called Cisco and I don't think the person i was talking to was too
aware of their products.
I looked at the PIX 535 and it has a VPN accelerator card, and allows for
3DES encryption.
This is a line from the product data sheet...

"168-bit 3DES IPsec VPN throughput: 100 Mbps" http://www.cisco.com/warp/public/cc/pd/fw/sqfw500/prodlit/535_ds.htm

However, this seems kind of contradictory that its 3DES and IPSEC...

Any suggestions?

DougM
07-13-2001, 02:59 PM
Try this chart: http://www.securitydogs.com/vpn_comparison.html


IPSEC is really a standard way of negotiatiting authentication and encryption so it may still use triple DES as an encryption algorythm.