Careful, he'll put you in his killfile and won't respond to you when you call him to task for incorrect information.
Careful, he'll put you in his killfile and won't respond to you when you call him to task for incorrect information.
Look at WatchGuard appliances and see what you think.
Is it not obvious?
*sigh* - this has nothing to do with my ego. It is very difficult to interpret your postings without having a sensible quotation of what you're referencing.
But: no worries, I will not answer any more, if I cannot interpret, what you want.
Yours, VB.
I don' t know the lineup -- which ones in particular are you suggesting? The family names aren't especially evocative to me.
-Russ.
I'm not suggesting any particular unit as I don't work for them, but I've always used their 1000 series (but you put that out of the price range a long time ago), they have x5 units and others that start in the price range in question. I'm not suggesting that any particular unit meets the criteria, but if anything does, it will be a WG unit.
X5 Firewall throughput: 80Mpbs. No mention of throughput with security features enabled. X15: 95Mbps.
Keeping in mind, even if you see 100Mbps, that's only 50mbps in each direction. Your server may well want to do 100Mbps full duplex with your lan. Furthermore, your internet traffic is still flowing through this box, taking up a portion of that banwidth. Finally, doing more than just stateful inspection will always be lower throughput than that, although WG doesn't seem to publish their numbers for that.
So, even the X50 which shows 100Mbps isn't really fast enough to run a heavily used server behind it in a DMZ. But it would be fine for, say an Intranet server or a mail server.
How much does the X50 cost?
-Russ.
The spec sheet says stateful inspection, that's it. Not IPS. That's what I'm referring to. Most boxes do stateful inspection at their full rated speed.
What does "removing malware from sessions" mean, exactly?
Yes, that's the point of the discussion. I said that sub $1000 firewalls can't do it. It was suggested by others that they can, but without any details or evidence. So I looked up the specs for them.
No, I haven't. I don't care. I worked on a WG once, and hated it. Other people seem to think they do 100Mpbs for less than $1000.
-Russ.
How do you know - you've done noting to determine what their 100mbps is doing for filtering. All of the spec sheets indicate throughput while providing protection - that means filtering.
I've been able to pull the sustained rate on all of their units while filtering the content using their proxy services and also removing malware from sessions.
Maybe you need to consider that a "heavily used server" that needs a FULL 100 MBPS in FD needs a full firewall with available bandwidth - and a sub $1000 firewall is not what you need for a "heavily used server". You should be sizing your firewall for the expected load.
Have you even looked? try
There are many different proxy services as rules for the firewall that can be used - SMTP and HTTP are examples. With the HTTP Proxy service I can remove many things and disallow content that is not specifically permitted - like cookies, activex, etc... In SMTP I can remove messages greater than X size, I can block attachments based on type, I can removed bogus/bad headers, I can do all sorts of things to remove malicious content and malware from HTTP and SMTP sessions.
The X15 is under $500 and does 95mbps, but I think that anything smaller than a X500 would be a waste on a high-use server.
I've worked with just about every firewall appliance on the market over the last 5 years and never found anything easier to use, never found anything that includes as many services/methods as the WG units in the same cost range....
What didn't you like?
What do you like better?
WG's are great. VPN Manager is great. Alas, my company outsourced the firewall to the telecom company.
The connection to the Internet is most likely going to be T1 or T3. That is 1.544Mbps or 45Mbps. This is easily handled by the X5 or X15.
What the poster doesn't seem to understand is that the Watchguard X series units are proxy based. That means they disassemble each packet to inspect it. This not a "packet filter" though WG can do that too. So having a proxy firwall that can run ~90Mbps on the external interface is pretty damn good.
I always install them with the Proxy services in order to provide that extra level of protection for users. The only drop-in ones I've installed are inside companies where I needed to separate the development teams / external contractors from the accounting/research departments.
Does it also re-assemble the packets into data streams to scan for things that span more than one packet? Many attacks can't be parsed out of single packets no matter how closely you stare at them. Of the boxes that do that, I haven't yet seen one that can do it as fast as it's rated stateful inspection capacity. Those are the types of advanced protections I'm talking about.
I really didn't like disjointed icon interface of the WG or the lack of configurable options on the site-to-site VPN setup, and the fact that it required an application install to manage it. The owners of it agreed, which is why I was there, installing a Fortigate in it's place. Which they now really like, having lived a year or two with the Firebox first.
-Russ.
What part could you not configure about site-to-site VPNs? They are highly configurable and can even specify ports, IP ranges, groups of ports/IP ranges, etc....
I couldn't specify DH groups and couple of the options like replay protection. If you're doing a connect between dissimilar boxes you need all the options. It also wouldn't let me specify the poxy-id's directly.
-Russ.
Have something to add? Share your thoughts — no account required.
Ask the community — no account required