Paid_Peanuts Posted December 14, 2021 Posted December 14, 2021 (edited) Assuming cost come back equal, which firewall + web filter would you deploy in your organisation tomorrow: Sophos XGS WatchGuard Fortinet Palo Alto Other We are currently investigating the list of vendors above for a multi site firewall project. If your chosen firewall provider isn't listed above, which would you choose and why? We would need the following functionality: Usual Firewall + Web Filtering Layer 7 App control DHCP server RADIUS accounting SD-WAN (site to site VPN) Interested to know everyone's thoughts. * disclaimer We are currently a Sophos XG house and we aren't unhappy with it, but we are not investigating the market to see if there is anything worth investigating. I'd be very interested to hear comments from those that moved from Sophos XG to something else and how they found the alternative. Usual grass isn't always greener... Edited December 14, 2021 by Paid_Peanuts
Davit2005 Posted December 14, 2021 Posted December 14, 2021 (edited) I've played with PFsense, DrayTek, and managed both SonicWall, Cisco ASA, PaloAlto and Draytek in the past I used PaloAlto for years at a previous place. They had an ASA 5500 series non FirePower before that and comparing side by side I'd say the interface on the PaloAlto wins. Filtering in the logs and firewall rules is easy and as it is an object/zone based managing rules is really easy, jus assign rules to different zones have the same rule include multiple zones, inter and intra zone rules, all the security rules are in one place/page and filters can be used to rules based on source and destination zones, objects, rule name containing specific words, destination or source IPs, etc. Site to site vpns and the GlobalProtect client vpn. The one thing to watch is the log retention for traffic logs on the PaloAlto is not great and if you have a lot of traffic it can soon fill up and overwrite older traffic logs so suggest another external log collector. Edited December 14, 2021 by Davit2005 1
bwestlake Posted December 14, 2021 Posted December 14, 2021 Personally Meraki or FortiGate Meraki SD-WAN is just so simple, however it is a little limited FortiGate gives you all those extra features 1
MatthewL Posted December 14, 2021 Posted December 14, 2021 I use Watchguard so maybe a little biased but you can manage them centrally even from putting a template to them (local rules can be added too), we have some 40 I think across sites and have in previous jobs had some 150 out there. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now