|
Posted by Leythos on January 25, 2007, 6:56 pm
If you were Registered and logged in, you could reply and use other advanced thread options
dball63@yahoo.com says...
> Our office is in need of a new hardware firewall. I've done a little
> homework and narrowed my selection down to 4 vendors. Was hoping some
> of you that have experience with some of these could share what you
> liked and or disliked about each. I've only worked with Sonicwall in
> the past and none of the others.
>
> Requirements:
> small footprint appliance
> Firewall/VPN for 15 PC LAN
> 5 VPN Client License Connections
> DMZ Optional
> Web Content Filtering
> SPAM Filter
> Virus Scan
> Intrusion Detection Protection
> 24x7 support for at least 2 years
>
>
> The 4 on my list are:
> Sonicwall TZ170
> Watchguard Firebox EDGE X15
> Zywall 5UTM
> Netgear FVS124G
Don't like Sywall at all, support sucks and they can't answer basic
questions.
Sonic, good generic firewall, lots of features, would be my second pick.
Netgear, well, they make nice low end devices and good switches, but,
they are my last choice in firewalls, but they are my only low-end
firewall choice when customers need something under $350.
WatchGuard, well, they are always my first choice and they offer devices
that do all that you ask, but the smaller units are not my first choice
- I never install less than an X500 unit.
DMZ - not optional.
Web Content filtering - this is vastly different depending on the
different products - as an example, HTTP Proxy service on WatchGuard
will allow you to block files based on extension, will block other
content, etc... You can also purchase "Web Blocker" that provides a
bunch of categories to allow/block and you can create different blocking
rules for different users/internal IP's.
Spam/Virus scanning - WG doesn't slow down when you add this, but, I
never install that on the firewall. I purchage a Exchange Server aware
product like GFI Mail Security and GFI Mail Essentials to do that.
ID - well, you have to have a real firewall, and if you want real
intrusion detection then you need something that also runs on their
nodes/workstations that interfaces with the firewall to block that
infected client.
24/7 Support - LOL, you can purchase it, but most of it's off-shore.
--
spam999free@rrohio.com
remove 999 in order to email me
|