Results 1 to 9 of 9

Thread: Work-related firewall query

  1. #1
    Will work for beer... nichomach's Avatar
    Join Date
    Jul 2003
    Location
    Preston, Lancs
    Posts
    6,137
    Thanks
    564
    Thanked
    139 times in 100 posts
    • nichomach's system
      • Motherboard:
      • Gigabyte GA-870A-UD3
      • CPU:
      • AMD Phenom II X6 1055T 95W
      • Memory:
      • 16GB DR3
      • Storage:
      • 1x250GB Maxtor SATAII, 1x 400GB Hitachi SATAII
      • Graphics card(s):
      • Zotac GTX 1060 3GB
      • PSU:
      • Coolermaster 500W
      • Case:
      • Coolermaster Elite 430
      • Operating System:
      • Windows 10
      • Monitor(s):
      • Dell 20" TFT
      • Internet:
      • Virgin Media Cable

    Question Work-related firewall query

    It looks like it's the end of the road for my much beloved and hitherto un-problematic 3Com Superstack 3 Firewall. It's been a good little box, sat in the corner, not complained about anything, handled a shedload of VPN traffic, but...it's got to go. The reason? While the IETF and a load of other companies (including THAT one) went one way on handling IPSec NAT-Traversal, 3Com went another. Guess who won?

    Anyway, I'm looking for a replacement. I could go Sonicwall - their 4060 looks a wonderful piece of kit for the purpose - and I'm considering Juniper's Netscreen range. I'm not antipathetic towards using a Cisco product, but here's the rub:

    VPNs. Windows has a perfectly acceptable L2TP/IPSec VPN client; supports 3DES, SHA-1 or MD5, works with RADIUS authentication, all that. If you apply a registry hack, you can even get it back to the pre-SP2 state regarding NAT-Traversal. So I DON'T want to have to spend X grand on a firewall that only works with VPN software that costs another £100+ for every client that I enable. No, I'm not making this up; just have a look at the pricing for, say, SoftRemote. I want to use the functionality already built in to XP.

    So, here's the rub; can anyone recommend a good firewall appliance that's up to handling a fair amount of usage from a moderately large company that'll support the XP VPN client natively?

    The first person that says "go build a Linux box" gets shot, by the way - seriously, this isn't a home project where I've got time to do a load of mucking around, entertaining and interesting mucking around, but still mucking around .

    Any OTHER ideas'd be greatly appreciated.

  2. #2
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    I'm not a big fan of Sonicwalls - their per user licencing annoys me.

    for low cost , have a look at the zywall set of kit , if the piggybank is looking fatter , then go for a watchguard.

    I@d like to play with cisco kit at some point too
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  3. #3
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    I've not tried using the watchguard IPsec vpns with anything other than the supplied softrempote. ( licence required :/ )
    however, they support pptp connections without any additional licences - I have one that holds 100+ clients at a time.
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  4. #4
    Will work for beer... nichomach's Avatar
    Join Date
    Jul 2003
    Location
    Preston, Lancs
    Posts
    6,137
    Thanks
    564
    Thanked
    139 times in 100 posts
    • nichomach's system
      • Motherboard:
      • Gigabyte GA-870A-UD3
      • CPU:
      • AMD Phenom II X6 1055T 95W
      • Memory:
      • 16GB DR3
      • Storage:
      • 1x250GB Maxtor SATAII, 1x 400GB Hitachi SATAII
      • Graphics card(s):
      • Zotac GTX 1060 3GB
      • PSU:
      • Coolermaster 500W
      • Case:
      • Coolermaster Elite 430
      • Operating System:
      • Windows 10
      • Monitor(s):
      • Dell 20" TFT
      • Internet:
      • Virgin Media Cable
    Yep; the Firebox X2500 might be a good option dependent upon the VPN support - I'm keen on IPSec/L2TP since PPTP's a bit anaemic, and I've set up a RADIUS server and everything... *whines*. Thanks for the suggestion. I'm also supposed to hear from Juniper today or tomorrow, and their Netscreens look very nice. Apparently the X2500 comes bundled with 1,000 Mobile User VPN licenses (which would seem to remove the necessity for additional software purchase for IPSec), so could be a VERY good option. Cheers, Moby.

  5. #5
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    look what I have on my desk....

    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  6. #6
    HEXUS.timelord. Zak33's Avatar
    Join Date
    Jul 2003
    Location
    I'm a Jessie
    Posts
    35,185
    Thanks
    3,126
    Thanked
    3,179 times in 1,926 posts
    • Zak33's system
      • Storage:
      • Kingston HyperX SSD, Hitachi 1Tb
      • Graphics card(s):
      • Nvidia 1050
      • PSU:
      • Coolermaster 800w
      • Case:
      • Silverstone Fortress FT01
      • Operating System:
      • Win10
      • Internet:
      • Zen FTC uber speedy
    /overwhelming desire to mention Zone Alarm and then run the hell away ever so ever so fast...but clearly its too childish to consider..so I'll leave !

    Nice red box Moby...

    Quote Originally Posted by Advice Trinity by Knoxville
    "The second you aren't paying attention to the tool you're using, it will take your fingers from you. It does not know sympathy." |
    "If you don't gaffer it, it will gaffer you" | "Belt and braces"

  7. #7
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    it is its a watchguard firebox ( about £2k of firewall - going into our suite at tiscali )
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  8. #8
    Will work for beer... nichomach's Avatar
    Join Date
    Jul 2003
    Location
    Preston, Lancs
    Posts
    6,137
    Thanks
    564
    Thanked
    139 times in 100 posts
    • nichomach's system
      • Motherboard:
      • Gigabyte GA-870A-UD3
      • CPU:
      • AMD Phenom II X6 1055T 95W
      • Memory:
      • 16GB DR3
      • Storage:
      • 1x250GB Maxtor SATAII, 1x 400GB Hitachi SATAII
      • Graphics card(s):
      • Zotac GTX 1060 3GB
      • PSU:
      • Coolermaster 500W
      • Case:
      • Coolermaster Elite 430
      • Operating System:
      • Windows 10
      • Monitor(s):
      • Dell 20" TFT
      • Internet:
      • Virgin Media Cable
    The X-series; I'm giving this a good hard look. Plus, as firewalls go, they look great. OK, that's a completely shallow and superficial criterion. But it's true all the same .

  9. #9
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    very much so - I think the older firebox III's looked cooler
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. are adverts the work of satan?
    By petrefax in forum Question Time
    Replies: 19
    Last Post: 19-12-2003, 11:57 PM
  2. Firewall preventing Network to work. (i thinik)
    By Dorza in forum Networking and Broadband
    Replies: 1
    Last Post: 02-12-2003, 08:21 PM
  3. Celeron M in Abit IS7 won't work!?
    By Mr Meltdown in forum PC Hardware and Components
    Replies: 2
    Last Post: 16-10-2003, 07:02 PM
  4. Next time you have a REALLY bad work day
    By Zak33 in forum General Discussion
    Replies: 15
    Last Post: 07-10-2003, 02:25 AM
  5. Taking my work home and then back again....
    By Nick in forum General Discussion
    Replies: 14
    Last Post: 19-09-2003, 09:47 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •