Jump to content

Recommended Posts

Posted

We are just about to move away from SEGFL broadband onto our own dedicated line. The firewall used to be managed centrally.

 

So BT have told me their router does not do NAT and we will need to purchase a dedicated firewall.

 

Can anyone recommend one?

Posted

Plenty of suggestions Palo Alto or Juniper depending on budgets and requirements. Used the Juniper SRX240 a few times very successfully, and currently looking at the Palo-Alto PA-4020 in a clustered config for a new connection :)

 

Fortigate is another one to look at (and can work out very cost effective), but the GUI/CLI isn't for everyone. Finally Watchguard is popular in the SMB segment. I'm not a fan, but know plenty of people that like them!

 

Are you looking for a UTM/Next-Gen firewall appliance with av scanning/IPS/Application identification or just a basic firewall? And what speed is your new connection? 10mb? 100mb? 1gbit? With some more detail can recommend specific products that would fit well :)

Posted

Its a 100mbit connection.

 

500 users a day.

 

I want a simple firewall basically, that's why its so confusing. Don't care about VPN, email, wireless or web filtering. Already got all that in place.

 

The watchgaurds look like they have a nice web interface but its a confusing area. Who are the market leaders?

Posted
We have Watchguards here too. Nice and simple to configure the firewall - setting up web filtering/spam filtering etc is a bit of a faff although the price for them makes up for it somewhat
Posted

Gartner have just published their 2012 UTM report (Magic Quadrant for Unified Threat Management) and then there's the Enterprise Firewall 2011 report (Magic Quadrant for Enterprise Network Firewalls).

 

Take what's in those with a bit of a pinch of salt (you need money to get into those reports), but essentially your looking at the normal names - Cisco and Juniper both being pretty big with Fortinet and Palo-Alto having strong positions (Juniper, Fortinet and Palo-Alto all stem from the same set of people buying/selling/creating companies ;) ). How much do you have to spend?

 

If your sure you only want firewall and will never want AV scanning or IPS or any other additional services then a Cisco ASA5505 or Juniper SRX100 or Fortigate-40C would all work. If you start looking at other services then you'll need to move to a bigger box to get full 100Mbps performance, but for purely firewalling those will all work and be in the £300 range without support/install costs.

Posted
Smoothwall can do just the standard Firewall - the rest is add ons - its fairly straight forward to configure

 

Thanks, just gave them a call.

 

Don't they price on clients though? Could be expensive for us.

Posted (edited)

Having spent weeks looking at these recently...

 

- Endian... roll your own server open-source product with a nice feature list but have to pay if you want support

- TMG... cheap on EES but quite limited (and runs on Windows, which is enough to make me say no straight away)

- Smoothwall... solid firewall & quality content filtering but no next-gen app level detection

- Fortigate... solid firewall, some basic app level filtering but only at a block \ allow level

- Sonicwall... promise a lot, seems to be love\hate with customers if it does what it says on the tin. Dell takeover muddies the waters

- Watchguard... lots of features, does app-level but I didn't like the interface and having web filtering on a separate box

(couldn't get a definitive answer from Watchguard on this as someone said on here it's all integrated now? They couldn't provide any education case studies either which didn't impress me)

- Palo Alto... the Audi \ BMW of firewalls... fantastic granularity, bandwidth control and reporting but you pay for the privilege

 

In the end we forked out for the Palo as if we don't control the student wireless our bandwidth will disappear the moment we turn it on. On the other hand I want to let genuine student web traffic through at full speed so being able to control bandwidth per app and see exactly what's going on is worth the £££ if you can get it. In these days of port 80 tunneling and web services I personally think app-level is a must-have.

 

Quick tip: if you're on EES buy Enterprise CALS and use Forefront Online Protection for Exchange for anti-spam filtering... save your bandwidth by doing it in the cloud and your monies by saving on firewall licenses ;)

Edited by gshaw

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...