best FW solution for <$2000

I work at a small software company (25 employees) and we have limited IT support (other than ourselves). We have limped along with consumer rated firewalls (Linksys), but now realize the importance of improving security and stability. We frequently use our Internet connection to move large files related to our business (some files ~500MB) every day. Also use for VPN access, customer portal, etc. No sensitive data like ecom.

I am looking at the Watchguard x55e. Any other suggestions?

Reply to
barnguy
Loading thread data ...

I can speak from experience that the Watchguard series has been hit and miss for several of my clients over the years. Their more recent offering have been decent but recent we lost a pair after a system outage (planned.) When we brought them back up our Firewall gurus complained that both units lost all of their config data. I haven't had an problems with Cisco products in general and quite frankly even an IPTables driven linux derived firewall has worked quite well (assuming you have staff that can manage it.) Based on my product notes the Firebox Edge x55e scored a B based on our last round of product evals. Not bad for the price.

The key question to answer is how much protection can you afford; and from there get the best product for the price range. I'm sure many of us could reccomend quite a few nice security products but reality defines that you can only get what you can afford.

If the Watchguard x55e fits into you budget, it seems like a very decent product for a small office solution but useability is the key. If a firewall is difficult to configure, then it's useless no matter what features it has. As a business you should purchase your products from a vendor willing to give you a good 15-30 day return policy or, depending on where you are, ask for an evaluation unit. This also provides a good test to see if your configuration can be backed up and restored to the unit you eventually purchase easily (don't send the eval unit back until the production unit is up and running.) Any decent vendor shouldn't have a problem with providing an evaluation unit. If you cannot find a vendor that will do that, see if you can contact Watchguard directly and ask if they have a demo unit they can ship you to try (Expect a deposit or shipping fees). A business' security is not to be glossed over nor should a firewall solution be implemented without a proper evaluation. Another option for a small business would be to see if you can find a managed firewall vendor and see what products and service they offer.

Reply to
Idgarad

Thanks for the direction. It was very helpful. Any chance you could recommend specific alternatives to the Watchguard?

Reply to
barnguy

The company I work for uses SonicWall. We two different models, SonicWall Pro 2040 and SonicWall TZ170. The Pro 2040 are quite expensive (around $4000) the way we have them setup (enhanced OS, premium filtering, gateway AV, etc.). But the TZ170 were less than a grand (standard OS, premium filtering, gateway AV, etc.). CDW carries them but we got a better deal from Dell.

Reply to
Hexalon

i forgot to mention that these devices also do VPN tunnels. The TZ170's are capable of 5 concurrently connected tunnels. The Pro

2040's are capable of 25 concurrently connected tunnels.
Reply to
Hexalon

I've got more than 60 WG units in the field and have been using them for more than 6 years in medical, small office, industrial, homes....

In all of those years I've not had a single unit fail. I still have 5 or

6 SOHO 6Tc units and a Firebox II that are in use in my lab.

The only time I've seen a config lost is when someone screwed up and either did a factory reset or downloaded a blank config to it.

Reply to
Leythos

Your firewall doesn't move files, your internet connection does and it would be the limiting factor in almost every case.

The firewall is going to be many times faster than any internet connection you can throw at it.

Linksys is not a firewall, it's a NAT with added features, but it's far from a Firewall.

If I were you I would look at the WG x550e series and not limit yourself at the lower end, but the 55 is a good unit.

Reply to
Leythos

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.