Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Enterprise firewall solution

Thread Tools
 
Search this Thread
 
Old 16 November 2002, 10:46 AM
  #1  
SD
Scooby Regular
Thread Starter
 
SD's Avatar
 
Join Date: Apr 2001
Posts: 678
Likes: 0
Received 0 Likes on 0 Posts
Question

Hi,

I've been looking for a 'proper' firewall solution to evaluate but am so far unsure of what's out there. We run Checkpoint FW1 in the office and I've also downloaded an eval of Symantec Enterprise Firewall, which looks OK but doesn't seem to do proxy arp (which we need).

Can anyone recommend any other solutions other than these two that:

1) Run on Win2000 server
2) Can proxy arp
and preferably
3) Have a VPN module as well.

TIA

Simon
Old 16 November 2002, 05:21 PM
  #2  
David_Wallis
Scooby Regular
 
David_Wallis's Avatar
 
Join Date: Nov 2001
Location: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Posts: 15,239
Likes: 0
Received 1 Like on 1 Post
Post

Raptor..

(we used to use it on NT) but now have about 6 Velociraptor boxes.. also one cisco..

David
Old 16 November 2002, 06:12 PM
  #3  
SiDHEaD
Scooby Regular
 
SiDHEaD's Avatar
 
Join Date: Apr 2002
Location: Birmingham
Posts: 9,196
Likes: 0
Received 0 Likes on 0 Posts
Post

If you want a proper hardware firewall, the one we have at work is faultless, and really simple to configure rules on etc.

WatchGuard FireBox

Andy
Old 16 November 2002, 08:39 PM
  #4  
WillieF
Scooby Regular
 
WillieF's Avatar
 
Join Date: Oct 1999
Posts: 778
Likes: 0
Received 0 Likes on 0 Posts
Talking

If you are looking for a 'proper' firewall have a look at Stonesoft.

Regular high scorer in reviews with clustering availabilty, multilink VPN, load balancing and an extremely good firewall.

No proxy arp however that can be run seperatly you could send me some details to my email address I will come up with a solution for you.
Old 17 November 2002, 07:03 AM
  #5  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Checkpoint FW-1 NG ???

Or am I missing something .......



Jeff
Old 17 November 2002, 11:42 AM
  #6  
what would scooby do
Scooby Senior
 
what would scooby do's Avatar
 
Join Date: Aug 2002
Location: 52 Festive Road
Posts: 28,311
Likes: 0
Received 0 Likes on 0 Posts
Post

Proper firewalls never run on OS's from Microsoft. It's like having a very secure front door but yer walls are made of tissue paper...

[Edited by what would scooby do - 11/17/2002 11:45:32 AM]
Old 17 November 2002, 01:24 PM
  #7  
krankyd
Scooby Regular
 
krankyd's Avatar
 
Join Date: May 2001
Posts: 672
Likes: 0
Received 0 Likes on 0 Posts
Post

nt firewall.

pap.

Get a cisco pix or nokia. A lot better
Old 17 November 2002, 05:46 PM
  #8  
Rusty Festa
Scooby Regular
 
Rusty  Festa's Avatar
 
Join Date: Oct 2002
Posts: 1,998
Likes: 0
Received 0 Likes on 0 Posts
Talking

How about a Sonicwall? They have a good range of dedicated boxes from teleworker right up to rack mounted corp solutions, inc VPN.

playing with a Sonicwall Soho at the moment
Jon

Edited to add: Someone is offering these through the Scoobynet shop I think

[Edited by Rusty Festa - 11/17/2002 5:49:18 PM]
Old 17 November 2002, 08:10 PM
  #9  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Question

My thoughts exactly Jeff!
Old 17 November 2002, 10:19 PM
  #10  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

I'm offering the SonicWALLs through the Scoobyshop as it happens...'cos we're SonicWALL resellers....

The arguement about the underlying OS is valid but, and it's a big but, a firewall running on Win2k which is understood by the support staff that maintains it will be more secure than the same software running on a platform that they have no experience off. Checkpoint runs faster in Linux than any other platform but corporates buy Nokia boxs to run their FW-1 on because it's pre-hardened.

There are a number of other 'appliances' that FW-1 runs on now or you could look at

Netscreen
SonicWALL
etc

Jeff



[Edited by Jeff Wiltshire - 11/17/2002 10:21:55 PM]
Old 18 November 2002, 08:11 AM
  #11  
chiark
Scooby Regular
 
chiark's Avatar
 
Join Date: Jun 2000
Posts: 13,735
Likes: 0
Received 0 Likes on 0 Posts
Post

I still know of a Nokia IP650 for sale if you want something that's generally recognised as good hardware to run the firewall on...

Grab yourself a bargain . Mail as per profile if interested.

Nick.
Old 18 November 2002, 08:29 AM
  #12  
SD
Scooby Regular
Thread Starter
 
SD's Avatar
 
Join Date: Apr 2001
Posts: 678
Likes: 0
Received 0 Likes on 0 Posts
Post

Thanks for the replies guys. Will look at them all! Jeff's point about the MS platform is valid - it may not be perfect but it's the OS we're strongest in and as such is obviously the first choice.

Time to start d/l'ing evaluation copies....

Simon

[Edited by SD - 11/18/2002 8:36:06 AM]
Old 18 November 2002, 08:43 AM
  #13  
TopBanana
Scooby Regular
 
TopBanana's Avatar
 
Join Date: Jan 2001
Posts: 9,781
Likes: 0
Received 0 Likes on 0 Posts
Question

Smoothwall?
Old 18 November 2002, 10:25 AM
  #14  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

On Win2K ???
Old 18 November 2002, 11:25 AM
  #15  
dsmith
Scooby Regular
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

FW-1 on Windows is fine - so long as the OS is hardened.

PIXs are only PCs in a cisco box running a cutdown *nix OS. The earlier ones are 100% standard ATX motherboard with standard components (bar the ISA flash card for the OS). Later ones are still PC based, albeit less standard - why else would you have USB ports

Deano
Old 18 November 2002, 11:33 AM
  #16  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Nokia boxs are again just a PC with a pre-hardened OS (IPSO).
Old 18 November 2002, 12:04 PM
  #17  
chiark
Scooby Regular
 
chiark's Avatar
 
Join Date: Jun 2000
Posts: 13,735
Likes: 0
Received 0 Likes on 0 Posts
Post

Absolutely

But we've still got one doing nothing
Old 18 November 2002, 12:33 PM
  #18  
beemerboy
Scooby Regular
 
beemerboy's Avatar
 
Join Date: Sep 2002
Location: Essexville
Posts: 4,391
Likes: 0
Received 0 Likes on 0 Posts
Post

i got a sonicwall pro, had it here for about a year, no problems.
except when i downloaded a bios update in japanese.

Do not do this, as japanese is hard to read.
...unless you are japanese, of course.

Jackie Chan.

Old 18 November 2002, 12:37 PM
  #19  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Lol @ Beemerboy

I've done that on a client site by mistake !
Old 18 November 2002, 12:44 PM
  #20  
beemerboy
Scooby Regular
 
beemerboy's Avatar
 
Join Date: Sep 2002
Location: Essexville
Posts: 4,391
Likes: 0
Received 0 Likes on 0 Posts
Post

haha Jeff, luckily, i was able to see the navigation path at the bottom of the IE window (in english), to get myself out of it...

it is a bit scarey though!! phew!!
hahaha - we live and learn. - excellent product though!!
BB
Old 18 November 2002, 01:54 PM
  #21  
dsmith
Scooby Regular
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

Obne of my colleagues was tasked with uploading a software update to a NetApp NetCache. We were a bit worried when the first re-boot didnt work. Then realised the poor thing was having trouble booting the PDF image of the Manuial instead of the OS

We may let him forget it ....one day

Deano

Old 19 November 2002, 12:46 PM
  #22  
HHxx
Scooby Regular
 
HHxx's Avatar
 
Join Date: Nov 2001
Posts: 2,576
Likes: 0
Received 0 Likes on 0 Posts
Wink

My vote goes to Fw1-NG. Currently building a FP3 version...

H
ps. Jackie Chan is not Japanese
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
dantiel
General Technical
8
29 September 2015 11:33 PM
jonnyricer2
Non Car Related Items For sale
2
16 September 2015 09:54 PM
BHPvstorque
Subaru Parts
2
16 September 2015 08:45 PM
riiidaa
ScoobyNet General
1
12 September 2015 11:52 AM



Quick Reply: Enterprise firewall solution



All times are GMT +1. The time now is 01:25 AM.