Small Form Factor Firewall

Small Form Factor Firewall

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Small Form Factor Firewall Will 09-27-2006
Posted by Will on September 27, 2006, 4:26 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Does anyone make a small form factor firewall that is manageable by a web
interface, with a rule based configuration similar in principle to
Checkpoint's, but is designed for individual computers or a very small
network? I'm interested in possibly putting a few of these in front of key
network management stations. Because of rootkit viruses, I no longer
believe that in what a software firewall's logs tell me. The rootkit can
simply hide network activity in the kernel and report back only what it
wants you to see. Because I would use these firewalls one per workstation,
I don't want to be spending $1K or $2K per box.

Some very desirable features:

1) A hard lockout on the firewall that would prevent any configuration
changes or administrative logins unless a button or knob were pressed.
Having a hard-wired read-only mode would prevent a trojan that sniffs your
keystrokes from doing much of use with the userid and password of the
external firewall.

2) Low cost, under $500/firewall.

3) GigE Support. These are being used on an internal network and I don't
want to sacrifice speed.

4) Support for mail alerts as well as alerting back to a GUI gadget on the
Windows desktop.

Are there any good options for this product?

--
Will



Posted by mak on September 27, 2006, 5:24 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Will wrote:
> Does anyone make a small form factor firewall that is manageable by a web
> interface, with a rule based configuration similar in principle to
> Checkpoint's, but is designed for individual computers or a very small
> network? I'm interested in possibly putting a few of these in front of key
> network management stations. Because of rootkit viruses, I no longer
> believe that in what a software firewall's logs tell me. The rootkit can
> simply hide network activity in the kernel and report back only what it
> wants you to see. Because I would use these firewalls one per workstation,
> I don't want to be spending $1K or $2K per box.

you could use a small soncwall (tz170)
> Some very desirable features:
>
> 1) A hard lockout on the firewall that would prevent any configuration
> changes or administrative logins unless a button or knob were pressed.
> Having a hard-wired read-only mode would prevent a trojan that sniffs your
> keystrokes from doing much of use with the userid and password of the
> external firewall.
>
it doesn't have a button but you can disable http/https managment on any
interface
(e.g. disable for inside/outside interface, enable for opt interface, if you
need to change config, connect with laptop
to opt interface or console)
> 2) Low cost, under $500/firewall.

i think they are about $400-500
> 3) GigE Support. These are being used on an internal network and I don't
> want to sacrifice speed.
>
not sure, check specs
http://www.sonicwall.com/products/index.html
> 4) Support for mail alerts as well as alerting back to a GUI gadget on the
> Windows desktop.
>
it can send mail alerts and I think syslogging
> Are there any good options for this product?
>

M

Posted by Leythos on September 27, 2006, 7:40 am
If you were  Registered and logged in, you could reply and use other advanced thread options
usc@noemail.nospam says...
> Does anyone make a small form factor firewall that is manageable by a web
> interface, with a rule based configuration similar in principle to
> Checkpoint's, but is designed for individual computers or a very small
> network? I'm interested in possibly putting a few of these in front of key
> network management stations. Because of rootkit viruses, I no longer
> believe that in what a software firewall's logs tell me. The rootkit can
> simply hide network activity in the kernel and report back only what it
> wants you to see. Because I would use these firewalls one per workstation,
> I don't want to be spending $1K or $2K per box.
>
> Some very desirable features:
>
> 1) A hard lockout on the firewall that would prevent any configuration
> changes or administrative logins unless a button or knob were pressed.
> Having a hard-wired read-only mode would prevent a trojan that sniffs your
> keystrokes from doing much of use with the userid and password of the
> external firewall.
>
> 2) Low cost, under $500/firewall.
>
> 3) GigE Support. These are being used on an internal network and I don't
> want to sacrifice speed.
>
> 4) Support for mail alerts as well as alerting back to a GUI gadget on the
> Windows desktop.
>
> Are there any good options for this product?

Almost every "Firewall Appliance" does what you want - check with
WatchGuard, call them to get the specifics you need to handle. Don't
settle for a NAT box, you will need a real firewall appliance.

What specifically do you expect the firewall to tell you and detect?


--

spam999free@rrohio.com
remove 999 in order to email me

Similar ThreadsPosted
Ip addresses: Converting from long form to dotted form in a shell script July 4, 2005, 2:13 am
Firewall and SSL working with Web Form info September 5, 2007, 4:45 pm
Firewall possibly dropping POST form data July 24, 2006, 4:12 pm
ASDM with two factor authentication October 7, 2008, 12:36 am
Solution for securing VPN using 2-factor SMS Authentication June 11, 2005, 1:11 pm
Cheapest Two Factor Authentication for Checkpoint? July 26, 2006, 2:51 pm
Small firewall March 2, 2005, 7:01 pm
Looking for a Firewall for a Small Business January 7, 2007, 12:32 pm
What firewall for a small network September 4, 2007, 9:49 pm
Firewall for small business environment April 15, 2005, 2:05 pm

The site map in XML format XML site map

Contact Us | Privacy Policy