Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Best software firewall - corporate use

Thread Tools
 
Search this Thread
 
Old 09 October 2003, 11:45 AM
  #1  
workshy_fopp
Scooby Regular
Thread Starter
 
workshy_fopp's Avatar
 
Join Date: Jan 2003
Posts: 757
Likes: 0
Received 0 Likes on 0 Posts
Post

Got 1,000 laptops, and we need a software firewall to protect them before/after they connect to the VPN.
Trialing Zonealarm Pro at the moment, but its really poor, won't save settings properly or act on those settings consistently, keeps prompting the user even though it's been configured not to.
What other software has anyone tried? What we want is zero user intervention or alerts.
Old 09 October 2003, 12:14 PM
  #2  
JR55
Scooby Regular
 
JR55's Avatar
 
Join Date: Jul 2003
Posts: 152
Likes: 0
Received 0 Likes on 0 Posts
Post

Checkpoint have a product that may be of interest, if you want I could sort out a trial for you. Drop me a line if you are interested.

Jon
Old 09 October 2003, 03:56 PM
  #3  
BlueBlood
Scooby Regular
 
BlueBlood's Avatar
 
Join Date: Jan 2003
Posts: 64
Likes: 0
Received 0 Likes on 0 Posts
Cool

Which VPN equip is it? It may be wise to integrate the two.
Old 09 October 2003, 05:38 PM
  #4  
stiler83
Scooby Regular
 
stiler83's Avatar
 
Join Date: Dec 2002
Posts: 448
Likes: 0
Received 0 Likes on 0 Posts
Post

Checkpoint Firewall 1 . CPFW1 can be a bitch to config and Admin if you are new. Have a look at.. http://www.phoneboy.com/fom-serve/cache/1.html

or a somthing like... http://www.nsa.gov/selinux/index.html

there is also www.Astaro.com
Old 09 October 2003, 05:56 PM
  #5  
workshy_fopp
Scooby Regular
Thread Starter
 
workshy_fopp's Avatar
 
Join Date: Jan 2003
Posts: 757
Likes: 0
Received 0 Likes on 0 Posts
Post

Using Cisco VPN and cisco client. Basically we need to protect them before and after they join the vpn tunnel, but the Zonelabs s/w is mickey mouse.
Old 09 October 2003, 07:27 PM
  #6  
stiler83
Scooby Regular
 
stiler83's Avatar
 
Join Date: Dec 2002
Posts: 448
Likes: 0
Received 0 Likes on 0 Posts
Post

You should be ok with a Cisco pix firewall making sure you have the latest ios.
Old 10 October 2003, 09:06 AM
  #7  
BlueBlood
Scooby Regular
 
BlueBlood's Avatar
 
Join Date: Jan 2003
Posts: 64
Likes: 0
Received 0 Likes on 0 Posts
Cool

The Cisco software firewall that is included with the client I feel is very good. Have a look at the .pcf file for it, u may be able to force he stateful inspection to always be on at startup & stop users from switching it off. Also if the clients are connecting to a Concentrator, you can configure very specific rules on the concentrators that are downloaded to the clients when the VPNs are established.

I would agree with the comments above, the Check Point is too much of a pain to manage & it costs a lot. The only thing I would add to the Cisco Concentrator solution is strong authentication - certs or secureID.

..r
Old 10 October 2003, 11:10 AM
  #8  
workshy_fopp
Scooby Regular
Thread Starter
 
workshy_fopp's Avatar
 
Join Date: Jan 2003
Posts: 757
Likes: 0
Received 0 Likes on 0 Posts
Post

We were using the Cisco stateful firewall, but it blocks most network traffic, i.e. we can't even ping the machine when it's running, so we're having to use a logon script to switch off the cisco service, then another one to start it when it connects to the VPN, then a logoff script to stop the service so the machine will behave normally when on the lan.
So we still need a software firewall for when they have got an IP address (from an ISP), but haven't connected to the VPN. We are using SecurID. I'll ask the comms guys to have a look at setting rules on the concentrator, sounds promising.

Cheers

Fopp (not being workshy for once)
Old 10 October 2003, 12:24 PM
  #9  
Chris L
Scooby Regular
 
Chris L's Avatar
 
Join Date: May 2000
Location: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Posts: 10,371
Likes: 0
Received 0 Likes on 0 Posts
Arrow

Try Sygate - better program than ZoneAlarm IMHO.

Chris
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
hardcoreimpreza
Computer & Technology Related
21
11 October 2015 03:40 PM
Brzoza
Engine Management and ECU Remapping
1
02 October 2015 05:26 PM
BlkKnight
Non Scooby Related
104
01 October 2015 09:40 PM
dantiel
General Technical
8
29 September 2015 11:33 PM
Wurzel
Computer & Technology Related
10
28 September 2015 12:28 PM



Quick Reply: Best software firewall - corporate use



All times are GMT +1. The time now is 03:24 AM.