Affordable UTM/IPS?

Affordable UTM/IPS?

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Affordable UTM/IPS? Xao 09-20-2008
Posted by Xao on September 20, 2008, 1:38 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


We are a small company that co-lo's currently two 1U servers with a 16
IP Block. We are now doing enough business to justify getting some
type of protection in front of our web/database servers (ecommerce)
other than just iptables.

In the height of our busy season, we will get close to 4 million hits
in a month and about 30-40GB of actual data movement over the Internet
pipe.

Primary purpose of the box would be to do firewall/IPS activity. Anti-
Virus scans on inbound mail would be a plus, but not necessary. Same
with one P2P VPN, but again, not necessary. We do not need all the
desktop AV, Spyware, etc... features as the box will not be located in
our office, just in front of our servers.

Budget is around $1,000 +/- a few bucks. Do not want anything like
Linksys or Dlink, but at the same time, we are not going to be
purchasing Cisco ASA's.

Any input would be appreciated.


Posted by Leythos on September 20, 2008, 3:08 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


In article <158d5d77-09db-49ee-94bf-c7838069a738
@k37g2000hsf.googlegroups.com>, te@ivorypetal.com says...
> We are a small company that co-lo's currently two 1U servers with a 16
> IP Block. We are now doing enough business to justify getting some
> type of protection in front of our web/database servers (ecommerce)
> other than just iptables.
>
> In the height of our busy season, we will get close to 4 million hits
> in a month and about 30-40GB of actual data movement over the Internet
> pipe.
>
> Primary purpose of the box would be to do firewall/IPS activity. Anti-
> Virus scans on inbound mail would be a plus, but not necessary. Same
> with one P2P VPN, but again, not necessary. We do not need all the
> desktop AV, Spyware, etc... features as the box will not be located in
> our office, just in front of our servers.
>
> Budget is around $1,000 +/- a few bucks. Do not want anything like
> Linksys or Dlink, but at the same time, we are not going to be
> purchasing Cisco ASA's.

Spend the money and get a WatchGuard X550e unit - has all that you want
and reports.

--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@rrohio.com (remove 999 for proper email address)

Posted by Todd H. on September 20, 2008, 3:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


> We are a small company that co-lo's currently two 1U servers with a 16
> IP Block. We are now doing enough business to justify getting some
> type of protection in front of our web/database servers (ecommerce)
> other than just iptables.
>
> In the height of our busy season, we will get close to 4 million hits
> in a month and about 30-40GB of actual data movement over the Internet
> pipe.
>
> Primary purpose of the box would be to do firewall/IPS activity. Anti-
> Virus scans on inbound mail would be a plus, but not necessary. Same
> with one P2P VPN, but again, not necessary. We do not need all the
> desktop AV, Spyware, etc... features as the box will not be located in
> our office, just in front of our servers.
>
> Budget is around $1,000 +/- a few bucks. Do not want anything like
> Linksys or Dlink, but at the same time, we are not going to be
> purchasing Cisco ASA's.
>
> Any input would be appreciated.

I've been very impressed with the IBM ISS Proventia Network MFS MX1004
hits your points, though I don't have a current price on it:

http://www-935.ibm.com/services/us/index.wss/offering/iss/a1027111

http://www-935.ibm.com/services/us/iss/pdf/multifunction_security_brochure.pdf

Its IPS functionality makes an ASA look positively pedestrian.
Excellent signature and behavior based AV. Has web filtering if you
want to use it.

Best Regards,
--
Todd H.
http://www.toddh.net/

Posted by Xao on September 20, 2008, 4:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


Yeah, at almost $15k, I would be impressed too. :) Sorry that's out
of our price range.

I just came across the SonicWall PRO 1260. Looks intriguing with the
built in switch, which would be perfect in our co-lo cabinet. Anyone
have any experience with it?


On Sep 20, 2:42=A0pm, comph...@toddh.net (Todd H.) wrote:
>
> I've been very impressed with the IBM ISS Proventia Network MFS MX1004
> hits your points, though I don't have a current price on it:
>
> =A0 =A0http://www-935.ibm.com/services/us/index.wss/offering/iss/a1027111
> =A0 =A0http://www-935.ibm.com/services/us/iss/pdf/multifunction_security_=
bro...
>
> Its IPS functionality makes an ASA look positively pedestrian.
> Excellent signature and behavior based AV. =A0Has web filtering if you
> want to use it. =A0
>
> Best Regards,
> --
> Todd H.http://www.toddh.net/


Posted by Todd H. on September 21, 2008, 12:52 am
If you were  Registered and logged in, you could reply and use other advanced thread options



> Yeah, at almost $15k, I would be impressed too. :) Sorry that's out
> of our price range.

Fortunately you're quite mistaken. The MX1004 is about $1500 or less
depending on the discount you manage. The price you quote sounds like
Proventia G class stuff. The signatures are identical in these
MX1004's though, and for your speed needs, they'll handle it tidily.

Recent review:
http://www.scmagazineus.com/IBMs-Proventia-Network-MX1004/Review/2351/




> On Sep 20, 2:42 pm, comph...@toddh.net (Todd H.) wrote:
>>
>> I've been very impressed with the IBM ISS Proventia Network MFS MX1004
>> hits your points, though I don't have a current price on it:
>>
>>    http://www-935.ibm.com/services/us/index.wss/offering/iss/a1027111
>>    http://www-935.ibm.com/services/us/iss/pdf/multifunction_security_bro...
>>
>> Its IPS functionality makes an ASA look positively pedestrian.
>> Excellent signature and behavior based AV.  Has web filtering if you
>> want to use it.  
>>
>> Best Regards,
>> --
>> Todd H.http://www.toddh.net/
>

--
Todd H.
http://www.toddh.net/

Similar ThreadsPosted
Affordable Firewall 4 Colo Server October 9, 2006, 12:01 pm

The site map in XML format XML site map

Contact Us | Privacy Policy