I agree, there are alternative solutions for customers that have a sole requirement of cost as their purchasing base, but, if the data is of value they may be undervaluing their need.
I agree, there are alternative solutions for customers that have a sole requirement of cost as their purchasing base, but, if the data is of value they may be undervaluing their need.
Not if you value data. Data has a price in most companies, and having a known workable solution is often safer than having "someone" build a open-source box that you have no certifications for, not specific tests that prove it's as secure as the appliance that's certified, etc....
If the value of the data behind the network is more than the cost of the firewall, then it's a no brainer. I once listened to a Best Buy sales rep tell a woman that she could protect her entire Accounting business behind a wireless router and that it was just plug-in and it would be ready to use - failing to mention that the wireless was totally open...
It was a 'known' bug with some X models that had (at the time) no cure from the vendor. Most generic models default to 1492, taking the max to 1500, and therefore working (in most cases)
Lucky for you ;-)
Comes down to your target market. I work in small organisations where $$ is a large factor. If they want a content-filtering firewall and the choice is to pay for 4 hours labour to build it and an old box, or nearly $12k in costs, subs and add-on fees, you can guess which path they will take.
Funnily enough, if either solution explodes, you can have another OS box in place the same day it goes rather than waiting 2-3 days for a vendor to ship a replacement and reactivate the feature sets for the new serial number.
Your most important point there was the 'certified' component. E.
That would be useless in the scenario the OP asked about. You *can* terminate the PPTP tunnels @ the border, but that means you either have to run the SBS box with a single NIC, or kill ISA/ publish Domain services on the 2nd NIC which should be filtering pretty much everything. It would be useful if you were only doing terminal services or similar, but for the same price you can purchase something that uses L2TP.
E.
With exchange rates that nearly doubles. I just priced on locally
Using e.g. IPCop and either one of their old boxes or supply one (p3
800, 128Ram, 20GB IDE, 52x CDrom) worth about $350. Add in 6 hours labour (@150 per hour) for building it, installing it, tweaking it and documenting it comes out @ $1250. Add in a donation of $200 to the OS makers to keep things moving. 1450. Assume that it blows up twice(even though this rarely happens) in 5 years and needs total replacement, the cost is $3950.$19471 + labour vs $1450 - $3950 including labour is a pretty major difference. This is not really a true picture as we charge less than $150 an hour. But those are the rates you can expect to pay from some providers.
If you were the bean counter of a small business or community org and that cost comparison landed on your desk, which way would you lean?
I have been in the situation of needing updates and support from open source, and found them quickly in the user forums. But there is no guarantee of quick support. Thorough testing of any platform is a given, as is knowing the best supported hardware, along with best practice configuration. These mitigate (and in some cases eliminate) the need for support from the vendor/provider.
I am not trying to say that OS is generically better, but in some instances it is a better solution to a customers needs. Particularly when the need is to 'not cost much'.
Hence the requirement for certified solutions, plus the business need for timely vendor support and the resultant budget allocation for same. You can do anything with a large enough budget ;->
I have had one fail (about 4 years ago). A new one was shipped promptly.
All WG's will do the basic connectivity functions out of the box so setup is a breeze (and I am sure you are thorough enough to backup the configs as standard practice and just reimport them if required), point is that feature sets (extra users, filtering etc) are activated against the serial number of the unit IIRC, and have to be transferred to the new unit in the event of a failure. Luckily, failures are rare. E.
I think you missed the point I was trying to make. You *can* do what you suggest, the question is whether or not you *should*.
internet -> [Router] < --Lanrange1-- > [SBSexternalnic|SBSinternalNic] [Internal PC's.]
If you terminate the PPTP session @ the router, it will have an IP* address on the outside interface of the SBS box. This means that you have to allow basically all traffic on what should be a filtering interface (e.g. only allowing PPTP, GRE, SMTP, HTTPS in). Standard SBS uses IPSec, NAT and port forwarding, Premium SBS includes all that plus ISA firewall.
If the SBS box terminates the PPTP session, the session will have an IP assigned via DHCP from the LAn/internal side of the SBS box. Impact is that next to nothing is accessible on the outside interface, unless you use an authenticated secure tunnel to get there. You can also enforce password security policies etc
SBS is best run with dual nics, with appropriate filtering and layers.
If it was a non-domain box, such as a terminal server behind the router than the product you mention would be a worthwhile solution. E.
*you will also have to set up rules to give individual clients specific IP's, or assign them @ the connectoid. If you run DHCP on the router SBS will have a kak.
Yup. that's the [router] bit above. Or [IPcop] or [smoothwall] or [whatever floats your boat]. All sitting on a seperate internal network range. Terminating public internet IP @ the server was not what I proposed.
I am not talking about exposing a server directly to the internet. Look at the diagram above. There is a router/firewall in front of it. This whole debate has been about what router would work best in such a setup, and trying to find something that passes inbound PPTP and GRE without fudging it. I have never met anyone that actually likes ISA, but it is quite robust when properly configured. Configuring it to do anything useful is basically a clusterf**k.
I also never terminate the WAN @ the server, but I prefer to use dual NIC's.
Yup. Same, but with dual nics.
Yes, I have installations where that is suitable. I also have sites where it isn't.
You have your preferred way of doing it, which works and stays working, I have my preferred way which also works, and stays working. E.
Cost is not the sole requirement. If you look at the price/features comparison in the previous post, the conclusion should be that price is the deciding factor.
The implication you are making here is ridiculous. E.
Have something to add? Share your thoughts — no account required.
Ask the community — no account required