Jump to content

Recommended Posts

Posted

Hi everyone,

 

Looking at investing in some infrastructure next year. We currently only have the hosted firewall on IPS's (RM) end.

 

I'd like to introduce our own appliance to supplement this and provide an additional element of security/control internally.

 

The Ubiquiti Dream Machine Pro caught my eye as I'm putting in all Unifi APs and would also be able to manage these without needing to faff around with cloud management, but I've read comments here suggesting that it's not really capable of carrying itself in larger networks - or is this only in the context of using it as a network core?

 

Maybe it's easier to list what we *don't* need an appliance to do:

- Network Core

- Filtering

- VPN

 

Anyone got any recommendations? This is very much new territory to me, never played with UTM/firewall appliances before. As I browse around options I'm finding licensing and cloud managed rabbit holes and it's a bit difficult to actually work out what I should be looking for.

 

I'm thinking of throwing in an LTE backup connection, probably limiting this to keeping critical services alive (cloud MIS/365-email/onedrive) in case of an outage. Be interested if anyone's got any experience to this effect? I'm thinking £15/20 a month on a data plan is going to be less hassle than FTTC/adsl connection. Something that can handle the failover connection is a must.

 

Cheers,

Ollie

Posted

I would not recommend a Dream Machine Pro even if you have other Unifi infrastructure they are not what they are meant to be and I am in middle of pulling one out not used as our main but as an endpoint it's not worth the hassle.

 

For me off shelf product would be Watchguard. Sophos UTM's are ok from what I've used but never myself deployed but have worked with them in place.

  • Thanks 2
Posted

Unifi routing/security products are not worth the effort as @MatthewL suggests.

 

Had a older USG pro and was ripped out after 6 months as it wasn't up to the job to firewall off a test network.

 

Fortinet fortigates are worth a look too. If you can afford it, Palo Alto might be something else to look at.

  • Thanks 1
Posted

I've still got one brand new sat in my store that was never used due to the first one been pants!

 

Palo Alto never used but have good recommendations out there.

  • 2 weeks later...
Posted
Hi everyone,

 

Looking at investing in some infrastructure next year. We currently only have the hosted firewall on IPS's (RM) end.

 

I'd like to introduce our own appliance to supplement this and provide an additional element of security/control internally.

 

The Ubiquiti Dream Machine Pro caught my eye as I'm putting in all Unifi APs and would also be able to manage these without needing to faff around with cloud management, but I've read comments here suggesting that it's not really capable of carrying itself in larger networks - or is this only in the context of using it as a network core?

 

Maybe it's easier to list what we *don't* need an appliance to do:

- Network Core

- Filtering

- VPN

 

Anyone got any recommendations? This is very much new territory to me, never played with UTM/firewall appliances before. As I browse around options I'm finding licensing and cloud managed rabbit holes and it's a bit difficult to actually work out what I should be looking for.

 

I'm thinking of throwing in an LTE backup connection, probably limiting this to keeping critical services alive (cloud MIS/365-email/onedrive) in case of an outage. Be interested if anyone's got any experience to this effect? I'm thinking £15/20 a month on a data plan is going to be less hassle than FTTC/adsl connection. Something that can handle the failover connection is a must.

 

Cheers,

Ollie

 

I'd be happy to provide some Sophos pricing for you - we can offer this as a supply only, or as a managed service (annual charg, co-managed). Drop me a PM if interested.

 

With 4G backup, just need to be certain that you have the data plan availability when you need it - i.e. if your main link is down, without significant traffic management, you are likely to need 100GBs+ of data. We offer an unlimited data plan on the 4G backup we deploy as resilience for our services for this reason. A consumer 'all you can eat' data SIM will have a 'small print' Fair Use Policy that will actually limit your data.

Posted

I would recommend WatchGuard or Untangle both products are great in a business\school setup. We have run with WatchGuard for years (we have two Fireboxes here at the mo a M470 and a T30) and they have been rock solid. We would not use them for web filtering the UI/UX for that part is very cumbersome. But all the other areas are great. As you stated you wanted failover etc the SD-WAN function works great. I have setup a few untangled setups for others and again its been great their are paid features that if you need you can add on easy.

 

The UDM/UDM pro are fine for home use (I use a UDM at Home fine its been great) but they are limited in what you can do in the firewall rules plus the new UI is incomplete and you have to keep switching back to the classic one.

Posted (edited)

Suggest a visit to Lawrence Systems YouTube channel.

 

It has been mentioned in more than one YouTube video review that the UDM Pro are not really up to much more than Pro home use or small business. In the best scenario a firewall will generally block traffic by default which in my opinion is the best way to go as traffic has to be specifically be allowed.

 

PfSense, Untangle and plenty other solutions out there but if you go pfsense whilst you can build on your own hardware for peace of mind I'd get a Netgate appliance. Depending what appliance you get these can be used and setup in a HA for very little cost in comparison to some of the top players. As you mention that you do not need the filtering package this will give you a good bit of choice as from my experience, very rarely is it able to find a firewall that has firewall and filtering to a very high standard i.e. filtering is generally easier for reporting and management on a dedicated filtering appliance. I've managed many different firewalls over the years including Cisco ASA, SonicWall, Draytek, PaloAlto and a few others. I don't think you can get much better than PaloAlto for usability, functionality and the tech though but it is not cheap with subscriptions for software and functionality.

 

When it comes to firewalls there are a few different types on how they work i.e. there are Zone/Object based, Interface (vlan or physical) based or a sort hybrid possibilities where rules can be applied to multiple interfaces at a time which make rule management easier. For example a rule on a Zone based firewall should be able to be easily copied/applied to other zones whilst on interface based it can be a chore to apply the same rule to other interfaces. You can also get 4G routers if the option of installing a sim card is not available on the actual hardware it self.

Edited by Davit2005
Posted
Suggest a visit to Lawrence Systems YouTube channel.

 

It has been mentioned in more than one YouTube video review that the UDM Pro are not really up to much more than Pro home use or small business. In the best scenario a firewall will generally block traffic by default which in my opinion is the best way to go as traffic has to be specifically be allowed.

 

PfSense, Untangle and plenty other solutions out there but if you go pfsense whilst you can build on your own hardware for peace of mind I'd get a Netgate appliance. Depending what appliance you get these can be used and setup in a HA for very little cost in comparison to some of the top players. As you mention that you do not need the filtering package this will give you a good bit of choice as from my experience, very rarely is it able to find a firewall that has firewall and filtering to a very high standard i.e. filtering is generally easier for reporting and management on a dedicated filtering appliance. I've managed many different firewalls over the years including Cisco ASA, SonicWall, Draytek, PaloAlto and a few others. I don't think you can get much better than PaloAlto for usability, functionality and the tech though but it is not cheap with subscriptions for software and functionality.

 

When it comes to firewalls there are a few different types on how they work i.e. there are Zone/Object based, Interface (vlan or physical) based or a sort hybrid possibilities where rules can be applied to multiple interfaces at a time which make rule management easier. For example a rule on a Zone based firewall should be able to be easily copied/applied to other zones whilst on interface based it can be a chore to apply the same rule to other interfaces. You can also get 4G routers if the option of installing a sim card is not available on the actual hardware it self.

 

 

+1 for Laurence Systems YouTube Channel, some good info about firewalls on there.

 

Can also recommend pfsense and opnsense as I’ve both used them in production

 

My home systems are currently handled by a virtual opnsense box I have 0% complaints a great open source firewall / router

  • Thanks 1
Posted

I'm running three Smoothwall S14's. I'd strongly recommend. They just do everything you need and the guys at Smoothwall will set them up for you too.

 

They've got a meatier appliance coming out soon too.

 

I've had pricing on replacing the S14's with Fortinet equivalent, I nearly fell out of my chair when I saw the price......

  • 3 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...