Perimeter Firewall/UTM Suggestions?

Perimeter Firewall/UTM Suggestions?

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Perimeter Firewall/UTM Suggestions? Paul Hutchings 08-18-2007
Posted by Paul Hutchings on August 18, 2007, 7:38 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I'm looking for a device to put at the edge of our network.

I would want it to do the following:

Act as a basic source/dest/protocol/action firewall to allow packets in
and out to/from our servers.
Have a minimum of 2 DMZ ports.
Allow the internal and DMZ interfaces to work in either NAT or Route
mode (selectable per interface).
Have some sort of URL filtering via an external database i.e.
Surfcontrol CPA/ISS
Have the means to add/exclude entire domains from this filtering.
Some level of IDS.
A/V would be nice but not essential.
Hardware appliance.

The basic scenario is that outbound access for our LAN users would be
handled by a proxy server on the LAN, so for outbound traffic (i.e.
concurrent users) all this device would ever see would be the external
IP of the proxy, as well as any traffic coming from our DMZ's.

The internet connection will be 100mbps, though I anticipate average
usage to be low, and bursty i.e. low average but when someone wants to
download a large file it'll burst to as fast as we can get it.

Because of this, and the fact that it won't have to handle connections
from hundreds of of LAN machines I'm hoping to be able to look at a
fairly low end box.

So far I've been looking (on paper) at:

Juniper SSG 140
Sonicwall 2040 and 3060
Checkpoint VPN-1 Edge
ISS Proventia MX1004

But of course there are many manufacturers out there.

I'd appreciate comments and suggestions.

cheers,
Paul

Posted by Leythos on August 18, 2007, 7:44 am
If you were  Registered and logged in, you could reply and use other advanced thread options
paul@spamcop.net says...
> I'm looking for a device to put at the edge of our network.
>
> I would want it to do the following:
>
> Act as a basic source/dest/protocol/action firewall to allow packets in
> and out to/from our servers.
> Have a minimum of 2 DMZ ports.
> Allow the internal and DMZ interfaces to work in either NAT or Route
> mode (selectable per interface).
> Have some sort of URL filtering via an external database i.e.
> Surfcontrol CPA/ISS
> Have the means to add/exclude entire domains from this filtering.
> Some level of IDS.
> A/V would be nice but not essential.
> Hardware appliance.
>
> The basic scenario is that outbound access for our LAN users would be
> handled by a proxy server on the LAN, so for outbound traffic (i.e.
> concurrent users) all this device would ever see would be the external
> IP of the proxy, as well as any traffic coming from our DMZ's.
>
> The internet connection will be 100mbps, though I anticipate average
> usage to be low, and bursty i.e. low average but when someone wants to
> download a large file it'll burst to as fast as we can get it.
>
> Because of this, and the fact that it won't have to handle connections
> from hundreds of of LAN machines I'm hoping to be able to look at a
> fairly low end box.

WatchGuard Firebox X755e - has up WAN, LAN, DMZ and you can add optional
5 other ports (as LAN, DMZ networks).

Does all that you ask above, good support, simple to learn, and if you
want GB network connections you can use the x1250e series.

--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@rrohio.com (remove 999 for proper email address)

Posted by Wolfgang Kueter on August 18, 2007, 11:32 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Paul Hutchings wrote:

> I'm looking for a device to put at the edge of our network.
> [...]
> So far I've been looking (on paper) at:
>
> Juniper SSG 140
> Sonicwall 2040 and 3060
> Checkpoint VPN-1 Edge
> ISS Proventia MX1004
>
> But of course there are many manufacturers out there.
>
> I'd appreciate comments and suggestions.

Personally I like the boxes from Clavister

http://www.clavister.com

and Fortigate

http://www.fortinet.com/

Wolfgang

Posted by Paul Hutchings on August 18, 2007, 12:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> Personally I like the boxes from Clavister
>
> http://www.clavister.com

Thanks, just checking those out now.

So far the ISS Proventia looks good.

Also looking at Network Box and Secure Computing Sidewinder - be
interested in any views on those.


Posted by on August 20, 2007, 10:47 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I second the Fortigate suggestion - although i do have a vested
interest www.fortiweb.co.uk


Similar ThreadsPosted
Suggestions for going beyond your average DMZ December 29, 2004, 8:30 am
suggestions for router/fw? May 1, 2005, 6:40 am
personal firewall suggestions November 14, 2005, 9:05 pm
Suggestions for a outbound firewall? July 10, 2008, 12:24 pm
internal firewall suggestions required May 11, 2005, 5:31 am
Suggestions for a gigabit speed SIP & RTP firewall September 2, 2005, 8:35 am
Suggestions on a Hardware .:Firewall-Router:. March 22, 2007, 6:20 am
open source web proxy suggestions ? September 27, 2007, 9:57 pm
How to annoy script-kiddies? - suggestions wanted January 8, 2007, 7:07 pm
Sample iptables rules list, inviting your suggestions / criticisms (thanks) :-) November 4, 2006, 3:47 pm

The site map in XML format XML site map

Contact Us | Privacy Policy