Jump to content

Recommended Posts

Posted

Evening all,

 

We currently run 2 watchguard firewalls, the XTM510 in both cases.

 

One runs a 10Meg BT leased line and the other a 100MB BT leased line.

 

Our current policy is to replace the firewall every 3 years, as it usually ends up being cheaper or a better deal to just buy new ones with 3 years full coverage than update the licencing on the old ones(or has the last 2 times). One X750e from the last refresh is currently being pfsensed and is going to run my home network :)

 

Now I have more clout, I would like to move away from WG, as I find them clunky with sporadic updates, a major list of bugs(I think it was one of the earlier 11.x updates ran the firewall for around a minute and a half and then CPU hit 100% and it locked up completely, WG just said wait for the next update!) and I think they could do better in handling our traffic (probably not scientific, as it depends on the testing end too, but speedtest.net usually shows us at 80 ish meg down and half that up)

 

Don't get me wrong, they do the job to the extent they work, but there must be better out there.

 

What do people suggest for the size of our 2 lines? The 100meg one also hosts about 20 websites, including VLE(moodle 2.3)and other animals, and around 10 VPN's at any one time from home users, and 3 branch office full time VPN's.

 

We aren't due to change till the end of this year, but I want time to investigate alternatives, so I can present my findings to SMT when the time comes.

 

Oh and the emphasis is on security as much as throughput, application based with group targeting would be lovely, as there are a few students who manage to install spotify on completely locked down computers in our computer rooms!

 

Thanks

 

James

Posted

We've been running with a Palo Alto firewall since June last year. Absolutely love it. We tried all the major vendors (Fortinet, Watchguard, Sonicwall, Barracuda, Cisco, Juniper, Checkpoint etc) and Palo Alto blew them all away.

 

We moved from a Juniper SRX to Palo Alto.

Posted
We're actually running a Watchguard XTM 820 and it handles our traffic very well - around 1000 client connections, plus all our inbound, and it handles all our intra-VLAN routing (it's the default gateway for all the VLANS). It also handles our main 100mb Internet connection and our backup ADSL link, with automatic failover configured. All of this and with WebBlocker and SpamFilter enabled, the loading and traffic indicators hardly register a thing.
Posted

While pFsense is fine for my home network, i would have great problems proving to SMT, that something i've cobbled together mysel matches up to a full paid for UTM appliance!! I know it can, but proving it to them is another matter!

 

thanks for the replies, interesting so far.

 

James

Posted
We've been running with a Palo Alto firewall since June last year. Absolutely love it. We tried all the major vendors (Fortinet, Watchguard, Sonicwall, Barracuda, Cisco, Juniper, Checkpoint etc) and Palo Alto blew them all away.

 

We moved from a Juniper SRX to Palo Alto.

 

Out of curiosity what was the price like? A few people on here say Palo Alto is very good but expensive....just curious what your experience of this was :)

Posted

True true, SMT do play a hard game of ball.

 

However PfSense is for more than just home, I have it on A network of over 500 people ;P lol

 

I have a meeting with Palo Alto next week, looking forward to it!

Posted

Hi,

 

It will in many ways depend on what exactly you are trying t get out of the firewall. We are partners with Palo Alto and SonicWALL, but each leads in a different way. The Palo will lead with application control and the idea of being able to control which applications can be used across a network. Firewall rules are then built from that. SonicWALLs will lead with firewall rules and then move on to application control.

 

We can arrange trials of both if you are interested and I will PM you with our details, so you can use them if they are of interest.

Posted
Out of curiosity what was the price like? A few people on here say Palo Alto is very good but expensive....just curious what your experience of this was :)

 

You can start with a PA 200, if you are only doing about 40 - 50mb/s of real world traffic and they are under £2k

Posted

All very interesting.

 

Now ive had some time to go through it, it would seem this time next year we will need 1 large device for the 100mbit, 1 medium device for the 10mbit(as it is a DR failover for the main site), and additionally 2 small devices for another 10mbit and a 4mbit EFM. I have managed to get them all to end at the same time, giving me some buying power! the other 2 devices are both at the moment, TZ210 SonicWalls, which are EOL soon enough anyway.

 

So added to my list is a centralised management console, so I can add sites to the blockers etc in one place rather than 4 places! Would be bliss!

 

Thanks for the input so far, and while the Palo Alto looks nice, it does seem on the steep end of things, does it have any extra functionality that warrants this/would enable me to sell it to SMT!

 

James

Posted

Hi,

 

Personally I would have gone for a failover pair of firewalls with a couple of switches that you could then connect all of your different circuits in to. I am presuming there is no real reason why they all have to separate firewalls as you can do all the nice firewalling and failover in one box really. If you are doing full DPI etc on the firewalls then I would suggest if you wanted to still with a SonicWALL, then something along the lines of a NSA 3500 or 4500 and if you wanted a Palo Alto probably a 2020 or 2050 would be fine. Palo are a little better on the DPI throughput so as a result you sometimes don't need such a hefty box.

 

More than happy to have a chat at any point.

Posted
That makes more sense. The 100mb/s link is the only one you need something more meaty on, but only if you are doing full deep packet inspection and application control. If it is just firewalling then an NSA250 upwards will do the deal on the SonicWALL front or a PA200 upwards on the Palo side of things

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...