Need Advice/Input on Router/Firewalls

Hi All,

I am in the process of researching router/firewall/vpn applicanes, and wanted some input from the community.

I have a somewhat complex network, with am internal NAT LAN, and an external DMZ zone with a block of public IP addrersses given to me by my ISP. I use that DMZ zone for mail servers and web servers. I also have several site to site VPN's.

My requirements are:

- URL/content filter and log

- Traffic QOS control in and out

- DMZ ports (or ability to configure ports as such)

- Dual WAN and automatic failover (Hight Availabiliy)

- VLAN Support

- IPSEC VPN- must allow roaming clients (connections from dynamic IP links)

- 19" rack mount is prefered

One reason for this is we are aquiring a backup Internet link (from the same provider, but on a different T-1 circuit). I need to be sure that when the primary link goes down or is flodded, the backup takes over- not only for the internal LAN, but for the hosts in the DMZ.

I have been looking at the D-Link DFL 1600- anybody have thoughts on that? It is a business class, and seems pretty new. I am trying to stay away from 3-com and Cisco simply becasue it is so very complicated (the equipment that matches my requiremments) and modulrized. I prefer an integrated, simple solution lilke the D-Link.

Thank you for your time!

Reply to
caryon
Loading thread data ...

At a cost of $7,000 retail, you should look at a WatchGuard X1000 Pro, with the Pro options you're cheaper than the 1600 and have all that you ask for.

formatting link

Reply to
Leythos

I did not see anything about vlan in the specs.

Reply to
caryon

Checkpoint FW1 Express (up to 500 users).

formatting link
Wayne McGlinn Brisbane, Oz

Reply to
Wayne

If the network is smaller and you don't have as much traffic coming through, you can check out the Check Point Safe@Office (with Power Pack for the vLAN and HA options). It's good up to 100 users. You can download the datasheet here:

formatting link

Reply to
TechGrrl

All Fortigates from the FG60 ($900) upward can handle your requirements. The only reason to move up to a FG100A ($1500)for example would be bandwidth, but two T1's without AV should be no problem for the FG60 unless you have *really* scary session counts.

You'll need an external logging package to handle the URL filter logs and reports, such as eIQ software ($700) or a FortiAnalyser appliance ($1500). Or some other open source/etc syslog package. But the filtering, configuration and blocking (plus basic logging) is done on the unit itself.

There are no per-node charges or limitations. VPN client software is like $15 a seat per year and includes optional AV, IPS, and personal firewall if you choose to include those components.

formatting link

-Russ.

Reply to
Somebody.

Quoting a bit of the post you're replying to might help, which box are you referring to?

-Russ.

Reply to
Somebody.

My suggestion as well.

Reply to
Katom

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.