Hardware Firewall Suggestions?

Author
Discussion

hutchingsp

Original Poster:

51,306 posts

211 months

Thursday 16th August 2007
quotequote all
We're upgrading our leased line to 100mbps.

Odds are the existing firewall (a Netscreen SSG 5) won't be up to the job and will need replacing.

The obvious choice appears to be the SSG 140.

Wondered what people here are using so I can look at the options?

We want the usual source/destination/protocol/action stuff, multiple DMZ/Configurable interfaces, and some level of Antivirus and Web Filtering would be useful to have i.e. integrated Surfcontrol as Juniper do.

hutchingsp

Original Poster:

51,306 posts

211 months

Saturday 18th August 2007
quotequote all
Bump.. anyone?

Seems there are lots of UTM devices out there.

The likes of ISS Proventia and Secure Computing Sidewinder look very good on paper.

CUE99T

1,021 posts

209 months

Saturday 18th August 2007
quotequote all
Hi mate, you had a look:

The Watchguard, Sonicwall, Cicso or Avocent ranges?

Saabyfox

2,229 posts

220 months

Sunday 19th August 2007
quotequote all
Always been a big Check Point fan......

hutchingsp

Original Poster:

51,306 posts

211 months

Sunday 19th August 2007
quotequote all
Thanks both.

Checkpoint are simply too expensive as they license on "Protected Nodes" and not "Connected Nodes" unless you look at their low end Edge series but they only have a single DMZ port.

I have looked at Watchguard and Sonicwall, can't quite quantify it they just don't fill me with confidence.

So far the two best candidates still seem to be ISS Proventia and Secure Computing SideWinder.

Problem is with all these things you're relying on the website and the manual before buying.

roadsweeper

3,786 posts

275 months

Sunday 19th August 2007
quotequote all
hutchingsp said:
I have looked at Watchguard and Sonicwall, can't quite quantify it they just don't fill me with confidence.
I'm surprised by that. I presume you've seen my email about our use of SonicWALL? Well, the datacentre guys themselves use Watchguard and swear by them so as far as I'm concerned (for what that's worth! smile) there's no real reason to worry to much about their efficiacy.

rednotdead

1,215 posts

227 months

Sunday 19th August 2007
quotequote all
Always had good results with the gnatbox range gta.com and their UK reseller gss.co.uk

no connection, just a happy customer.

guydw

1,651 posts

284 months

Sunday 19th August 2007
quotequote all
I'd stick with Netscreen - I reckon it's the market leader. It's Juniper so it won't break.

Checkpoint also very good - Crossbeam platform is the best - but mucho wonga.

PIX is very good, universally used, probably the network guys choice as it has a proper command line.

ThePassenger

6,962 posts

236 months

Monday 20th August 2007
quotequote all
Another vote for Watchguard here I'm afraid. Last time I played with one it was basically an embedded Linux system running iptables, easy to configure, monitor... rock solid and proven tech.

dgardner13843

5 posts

201 months

Monday 20th August 2007
quotequote all
Good Afternoon Paul

I work with PING IT Services which is "CUE 99T's" company. With regards to your Firewall requirements we may be able to help you.

How would you like a Sonicwall Pro 4060 to try free of charge for 1 month. I can arrange this no problem for you if that is of interest. Please let me know?

Best regards

David

hutchingsp

Original Poster:

51,306 posts

211 months

Monday 20th August 2007
quotequote all
Cheers all. We have an existing supplier for Sonicwall and they're of the opinion that Juniper are a more rounded option.

I'm awaiting pricing from ISS and Secure Computing as they do look to be exactly what I'm after, so we'll see what they say.

spivvy

1,534 posts

255 months

Monday 20th August 2007
quotequote all
another one to consider is a fortigate system ,just putting one it at the moment as we had to replace the checkpoint can't give comments yet as it is new to me but

comes complete with anti virus, anti spam, web traffic monitor, vpn client



http://www.fortinet.com/

Edited by spivvy on Monday 20th August 20:48