Results 1 to 12 of 12

Thread: firewall/router for SME / SOHO

  1. #1
    Senior Member
    Join Date
    Oct 2005
    Posts
    320
    Thanks
    3
    Thanked
    1 time in 1 post

    firewall/router for SME / SOHO

    Our cisco pix 501 died over the weekend and I'm trying to find a replacement, we've been recommended the cisco ASA 5505 50user by our external IT support, but they are quoting an extortionate amount. I'm thinking (a) it does things that I don't need (b) doesn't do other things that I would like (c) overall seems to be a bit expensive for something I'm not happy with

    Can anyone here suggest a suitable firewall/router?

    I'm not sure on the throughput requirements - which seem to be the most significant factor when it comes to cost, but we have about 15 users in the office who connect to a server, this is all on one subnet and doesn't touch the firewall. I would also like a seperate terminal server (which will have at most 5 external users at any one time) to be on a seperate subnet which is firewalled from the main office network, the terminal server will need to be able to connect to the sql databases on the main network.

    The terminal server currently has OpenVPN set up for the external users to connect, our IT support people would like to be able to use a VPN on the firewall, they apparently prefer cisco, but can cope with most things

    I'm also thinking that would should go wireless, so incorporating that into the firewall seems like a good idea

    I've been looking at the
    - zyxel zywall 2wg
    - draytek Vigor 2910VG

    any thoughts?

    Thanks

    [edit]I forgot to mention, it will need to do multinat (I don't know the proper term) such that
    1 external IP goes to the terminal server which also has its own internal IP
    1 external IP maps to the main server which also has its own internal IP
    all office / user PC's map to a 3rd ip

    I was looking at the zyxel and couldn't decide if this was possible
    Last edited by pak000; 13-05-2009 at 09:50 PM.

  2. #2
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: firewall/router for SME / SOHO

    The Drytek are pretty highly regarded and I have seen them in the sort of situation you describe - and considering the capabilities, not outrageously expensive either - so worth a punt anyway.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  3. Received thanks from:

    pak000 (15-05-2009)

  4. #3
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: firewall/router for SME / SOHO

    we have recently started to replace Drayteks with 800 series routers and ASA 505
    □ΞVΞ□

  5. #4
    Senior Member
    Join Date
    Feb 2008
    Posts
    925
    Thanks
    4
    Thanked
    161 times in 148 posts
    • smargh's system
      • Motherboard:
      • Gigabyte GA-EP45-UD3P
      • CPU:
      • Xeon E5450 with 775-to-771 Mod
      • Memory:
      • 16GB Crucial
      • Storage:
      • Intel X25-M G2 80GB/Adaptec 3405 4x 2TB Ultrastar RAID1 / 1x 6TB Hitachi He6 / Dying 2TB Samsung
      • Graphics card(s):
      • GTX 750 Ti
      • PSU:
      • Seasonic X-560
      • Case:
      • Lian-Li PC-A71
      • Operating System:
      • Windows 7 Ultimate 64bit
      • Monitor(s):
      • BenQ G2400WD
      • Internet:
      • Really Crap ADSL2 <3Mbit

    Re: firewall/router for SME / SOHO

    http://m0n0.ch/wall/ (lean) or http://www.pfsense.com/ (less lean)
    Both have VMWare images you can test things with.

    Hardware - completely fanless, small, nifty, useful! I own an old Wrap board and a newer Alix. They are awesome.
    http://linitx.com/viewcategory.php?catid=176&pp=176

    Perhaps plus a VPN accelerator card (56eur from http://soekris.eu/shop/vpn_boards/vp...ockets_en.html). Googling suggests 25Mbit+ without one.

  6. #5
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: firewall/router for SME / SOHO

    smargh they are all very good, don't get me wrong, but I just don't think they are the correct way to go this time.
    □ΞVΞ□

  7. #6
    Senior Member
    Join Date
    Feb 2008
    Posts
    925
    Thanks
    4
    Thanked
    161 times in 148 posts
    • smargh's system
      • Motherboard:
      • Gigabyte GA-EP45-UD3P
      • CPU:
      • Xeon E5450 with 775-to-771 Mod
      • Memory:
      • 16GB Crucial
      • Storage:
      • Intel X25-M G2 80GB/Adaptec 3405 4x 2TB Ultrastar RAID1 / 1x 6TB Hitachi He6 / Dying 2TB Samsung
      • Graphics card(s):
      • GTX 750 Ti
      • PSU:
      • Seasonic X-560
      • Case:
      • Lian-Li PC-A71
      • Operating System:
      • Windows 7 Ultimate 64bit
      • Monitor(s):
      • BenQ G2400WD
      • Internet:
      • Really Crap ADSL2 <3Mbit

    Re: firewall/router for SME / SOHO

    Quote Originally Posted by Jay View Post
    smargh they are all very good, don't get me wrong, but I just don't think they are the correct way to go this time.
    The hardware, or pf/m0n0?

  8. Received thanks from:

    pak000 (15-05-2009)

  9. #7
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: firewall/router for SME / SOHO

    the software. I think a solid asa would be the best choice
    □ΞVΞ□

  10. Received thanks from:

    pak000 (15-05-2009)

  11. #8
    Senior Member
    Join Date
    Oct 2005
    Posts
    320
    Thanks
    3
    Thanked
    1 time in 1 post

    Re: firewall/router for SME / SOHO

    Thanks for your input.

    I'm reluctant to go down the cisco route, I know they are good quality and more than up to the task, I just feel their cost for what we need is a little excessive, I'm also aware that they arn't exactly the most user friendly devices.

    smargh - building a router would be fine, but unfortunately I don't have the time at work to be experimenting with set ups I've never come across before - IT isn't my main job, it's just dumped on me like in a lot of small offices

  12. #9
    Senior Member
    Join Date
    Sep 2003
    Posts
    593
    Thanks
    0
    Thanked
    1 time in 1 post

    Re: firewall/router for SME / SOHO

    Zyxel make pretty decent stuff. It's not quite as configurable as the Cisco and doesn't have some of the high end features. The NAT thing worries me slightly. I don't know if they'll do full NAT like an ASA or other high end firewall would. I think the zywall 35 did but I can't remember if the lower end models did.

    What you're talking about with the differently rulled subnets is just a DMZ as far as I can see. Again the zywall 35 did it, not so sure about the lower end models.

    You'll struggle to find a new PIX because they're no longer sold.

    Also you're just doing NAT. You just need to have enough public IPs to cover your NAT rules or your going to be getting into PAT, and I'd try to stay away from that.

  13. #10
    Senior Member gss03's Avatar
    Join Date
    Jul 2003
    Location
    Scotland
    Posts
    725
    Thanks
    6
    Thanked
    28 times in 28 posts

    Re: firewall/router for SME / SOHO

    Personally if its for a Business I'd go with the Cisco recommendation - Their your IT company. They wouldn't recommend it if it didn't do the jobs you ask of it.

    After that my order of preference would be
    - Draytek
    - Zyxel
    - Sonicwall

  14. #11
    Registered+
    Join Date
    Aug 2008
    Posts
    18
    Thanks
    0
    Thanked
    1 time in 1 post

    Re: firewall/router for SME / SOHO

    D-Link has a UTM firewall for SME/SOHO coming out in Q3 sometime. They are usually fairly good at SME/SOHO networking equipment. Model is DFL-160. Perhaps worth having a look. Details can be found by googling the model name.

  15. #12
    Not a good person scaryjim's Avatar
    Join Date
    Jan 2009
    Location
    Gateshead
    Posts
    15,196
    Thanks
    1,231
    Thanked
    2,291 times in 1,874 posts
    • scaryjim's system
      • Motherboard:
      • Dell Inspiron
      • CPU:
      • Core i5 8250U
      • Memory:
      • 2x 4GB DDR4 2666
      • Storage:
      • 128GB M.2 SSD + 1TB HDD
      • Graphics card(s):
      • Radeon R5 230
      • PSU:
      • Battery/Dell brick
      • Case:
      • Dell Inspiron 5570
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 15" 1080p laptop panel

    Re: firewall/router for SME / SOHO

    The unit I currently work for uses a Watchguard Firebox X. I won't go into the crazy-mad way we're using it, but I've found it to be incredibly reliable, easy to configure - pretty much issue free. Of course, it may not be entirely suitable for your needs, but they could well have something worth looking at their range: http://www.watchguard.com/

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Headlines - Sexy SOHO NAS with RAID 50 and 60
    By Nick in forum HEXUS News
    Replies: 2
    Last Post: 07-06-2008, 12:59 AM
  2. Cheap(ish) firewall/router
    By 0iD in forum Networking and Broadband
    Replies: 9
    Last Post: 07-05-2007, 03:28 PM
  3. SOHO - Image Request
    By Matt1eD in forum Consumer Electronics
    Replies: 2
    Last Post: 03-10-2006, 01:59 PM
  4. Firewall/Router Pricecheck
    By 0iD in forum PC Hardware and Components
    Replies: 1
    Last Post: 23-08-2005, 07:20 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •