Firewall Recommendations Needed from the Secuity Group

Our office is in need of a new hardware firewall. I've done a little homework and narrowed my selection down to 4 vendors. Was hoping some of you that have experience with some of these could share what you liked and or disliked about each. I've only worked with Sonicwall in the past and none of the others.

Requirements: small footprint appliance Firewall/VPN for 15 PC LAN

5 VPN Client License Connections DMZ Optional Web Content Filtering SPAM Filter Virus Scan Intrusion Detection Protection 24x7 support for at least 2 years

The 4 on my list are: Sonicwall TZ170 Watchguard Firebox EDGE X15 Zywall 5UTM Netgear FVS124G

David

Reply to
Dball63
Loading thread data ...

Don't like Sywall at all, support sucks and they can't answer basic questions.

Sonic, good generic firewall, lots of features, would be my second pick.

Netgear, well, they make nice low end devices and good switches, but, they are my last choice in firewalls, but they are my only low-end firewall choice when customers need something under $350.

WatchGuard, well, they are always my first choice and they offer devices that do all that you ask, but the smaller units are not my first choice

- I never install less than an X500 unit.

DMZ - not optional.

Web Content filtering - this is vastly different depending on the different products - as an example, HTTP Proxy service on WatchGuard will allow you to block files based on extension, will block other content, etc... You can also purchase "Web Blocker" that provides a bunch of categories to allow/block and you can create different blocking rules for different users/internal IP's.

Spam/Virus scanning - WG doesn't slow down when you add this, but, I never install that on the firewall. I purchage a Exchange Server aware product like GFI Mail Security and GFI Mail Essentials to do that.

ID - well, you have to have a real firewall, and if you want real intrusion detection then you need something that also runs on their nodes/workstations that interfaces with the firewall to block that infected client.

24/7 Support - LOL, you can purchase it, but most of it's off-shore.
Reply to
Leythos

just to give a second opinion, since that's what you asked for,

If you worked with Sonicwall, I would stick with it. We have about 120 tz 170's out there, and they seem the right choice in your case.

2nd choice: watchguard 3rd netgear (don't know this model, but it's got to be better than) 4th zywall

that would be my order.

Reply to
mak

Hi David,

You may also wish to visit the individual forum for each vendor:

formatting link
Sincerely,

Brad Reese Cisco Resumes

formatting link

Reply to
www.BradReese.Com

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.