Jump to content

Recommended Posts

Posted

Hi,

 

Just wondering if anybody here is using the firewall and filtering, and if you are what are your opinions on it?

 

Thanks in advance guys/gals

Posted
We've got one as part of our Virgin Media package, personally I think they're quite good, the amount of stuff you can do on them is amazing. The only problem we have is Virgin Media lock some of the features out of ours, so we can't do simple things like create a new user account for an admin on it.
Posted

What do you want to know... We are running a PA3020.

 

Aside from an RM system service that keeps hijacking the logged on user we are very happy with it. There are very few limits to what you can do with it.

 

It's not a cheap option, but I really feel it is worth the money. The only thing I would say is to not get it from Gamma networks as there support is pretty much first line only, anything more complicated goes to exclusive networks who appear to be Palo's major UK partner. I would look to buy direct from them.

Posted

Talk to Net-Ctrl - it's who I bought the PA3020's I was running from :).

 

As others have said it's an amazing bit of kit. When people say Palo Alto is the Rolls Royce of the firewall world they're not kidding. We tested PA kit against lots of others (Juniper, Checkpoint, Fortinet, Watchguard, Sonicwall) and it was simply the best at everything we got it to do. The application and user level filtering was just lightyears ahead of what the other products were able to do. They may say they can do it, but none worked anywhere near as well as the PA implementation ;).

 

If you've got the cash for them I'd recommend Palo Alto without a second thought.

  • Thanks 1
  • 1 month later...
Posted
To all the people using Palo Alto for filtering? - how are you enforcing google safe search? As I understand the unit cannot enforce this setting which seems astonishing for such a feature rich piece of kit.
Posted

I had this demoed to me last week from Virgin.

 

My other option at the moment is smoothwall and again had that demoed last week

 

Just waiting for the pricing on the smoothwall to compare

Posted
we have enforced safesearch like @Michael has shown in the link, but after a long conversation with Palo Alto, they have told me that the next software update will include a check box to force safe search. It's due sometime soon.
Posted
As we are still an XP network, we have IE disabled for compatibility reasons, and then we have google chrome installed and controlled by GPO, which enforces safe search.
Posted (edited)
It's in the v6 version of there software will be installing this later today

 

We have V6 just testing it now....

Edited by steele_uk
Posted (edited)

I have just had a trial of a Fortinet device, and am currently in the second week of a Palo Alto trial. I managed to persuade the supplier to set up the Palo as a fully operational firewall and filtering device, rather than the in-line mode they usually advocate. This has allowed me to trial it in more detail, as it is functioning as it would if we were to go ahead and buy.

 

I have the budget approved for both the Fortigate and Palo Alto.

 

At the moment I am just really not convinced by all the praise that the Palo Alto receives. I am not thoroughly persuaded at the moment that it does anything more than slightly better than the Fortigate. It is very expensive. I see also that the log size is somewhat limited on the box (PA 3020), and the supplier suggests buying the Panorama product. This is another several thousand pounds!

 

The Safe Search feature works, but it is annoying. With the Fortigate device it worked without bothering anyone. The Palo Alto insists that you set your own Safe Search to 'filter explicit results'. This is currently causing disruption to students and staff, as well as increased calls to support, as many people see an 'error' and immediately freeze and call IT support.

 

I have trialled Sonicwall, Cyberoam, Watchguard, Smoothwall, Fortinet, Palo Alto, and considered Lightspeed, Bloxx, Sophos, Meraki, Cisco, Juniper, and Barracuda. They are all lacking in some significant way that makes the perfect solution (for us) possibly a combination of two of them. However, we can't afford that, and so I will have to make a compromise. This is why I need something that fits as closely as possible. Therefore it will likely be Fortinet or Palo Alto.

Edited by SJA
Posted

We got a Palo Alto firewall with our Virgin package. So far I have to say it is very good! Not just hype but actually does the job. We run our filtering via Bloxx though so can't comment on that side of things.

 

As mentioned earlier in the thread, some parts are locked out by Virgin but nothing that we really would need to access. I can get full control over the NAT and security settings plus the monitoring logs. Don't need anything else :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...