Jump to content

Recommended Posts

Posted

If we were to get a dedicated line into our school instead of the LEA broadband what would people advise for a firewall? Many moons ago we used to use an ISA box - but this was software based. What options are there out there?

 

Thanks

 

Gareth

Posted

What do you want it to do? Just a firewall? If so I would recommend Sonicwall. I am quite pro Cisco, but I feel the Sonicwall is much better value.

 

You could look at using something like PFsense that is free?

Posted
If we were to get a dedicated line into our school instead of the LEA broadband what would people advise for a firewall?

 

After a discussion yesterday me and our external IT consultant had about possible cloud setups, we might consider Untangle. Seemingly the same software install can run on dedicated hardware (Linksys routers, in particular, I think) or as a cloud install. This would allow us to create a VPN to an AWS Virtual Private Cloud (and also out to a third building we use) all on the same software.

Posted
Is it just a firewall you need - or do you want it to do filtering? I always think that filtering and firewall are best done together because its not just filtering web traffic any more, but allowing or not allowing "App" traffic for which you need signatures and you need to combine that with URL permissions.
Posted
We have 4 shiny new bright red Watchguards ready to go in, and 4 grey, drab and annoying sonicwalls coming out :)

 

You wont be disappointed we only have one M400 and a T30 here.

Posted
2 M300 and 2 M500 here :) We used to use them years ago, but on the last refresh we weighed up sonicwall against them and sw came out on top for specs and most services, then Dell bought them...I don't think I have seen a firmware update in 18 months, the sonicpoint AP system is a constant thorn in my side, etc, etc.
Posted

Whatever you use have a real good in-depth look at its SSL abilities or if it can handoff SSL to endpoint protection.

 

I'd also recommend (if possible) stress testing the throughput of SSL on the vendors firewall in earnest as we find that very often the throughputs given of various boxes do no ring true in a real world environment.

 

E.g. App control can be pretty useless if the traffic is end to end encrypted over SSL and your firewall can't do a man in the middle attack as it won't know what the traffic is if it goes out of a normal port e.g. 443.

 

Good luck

 

Dave

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...