Small office firewall/vpn/security appliance

Sep 24, 2005 33 Replies

Great info - but I'm still not sure if your can use the hardware ports as lans - perhaps I should just tell you what I would like to do.

I would like the normal untrust, DMZ and internal trust lan plus a "sort of trusted" lan for a guest wireless segment and a second DMZ on which I will connect a windows box we keep on the "outside" for Netmeeting and some other services. But the I don't really want the windows box to have access to the "real" server in the DMZ since it could get more easily compromised.

The Netmeeting box allows us and others to connect to it from behind firewalls since it has a static IP.

Thanks again !

Well, you still have WAN2 left to use as needed, you've occupied WAN1, Internet, DMZ. Note that the names are completely arbitrary, you could readily install it backwards or assign them to any arbitrary role. Their being hardcoded as they are is a somewhat unfortunate fact; you can abstract them by creating more aptly named zones and putting one interface in each zone, then building all your policies on zones. This also allows you to change interfaces around by simply switching the zone definitions in your config. But anyway, back to the question:

1) You could put the WAP and the NM server on the same subnet on WAN2. (bad, wireless could hit NM server directly) 2) You could configure the NM server on VLAN1 and put VLAN1 in a new zone called DMZ2 using the WAN2 interface. That gives you a completely separate zone and set of policies. Then put the WAP on the WAN1 interface the normal way. (preferred, full control) 3) You could put a secondary IP on the WAN2 interface and configure the WAP for the secondary IP and the NM server on the primary network. The put in a WAN2 :: WAN2 deny policy to prevent traffic between them. (next best after vlans, bad because if wireless could somehow figure out to add a second IP on their NIC in the right range, they could hit the NM server directly. Unless your WAP can be configured to block such traffic)

-Russ.

For roughly double the price, yes.

-Russ.

So you want a WAN, LAN, DMZ, DMZ networks - that means 4 ports/jacks with rules for each.

The WatchGuard Firebox X700 with the Pro upgrade will give you 6 different network ports and allow you to setup like that.

Well I have clients who had to toss out early FG50's because the AV killed mail connections.

I'm not just talking the US judgement, I'm talking the European judgement as well, how much faith can you put in a security company that steals code to make its products? One of the byproducts of the European judgement is that Fortinet have to publish their source when requested to whomever requests it. Not exactly the kind of thing you want at this level of security.

You are aware of the other problems they are having? That they used unlicensed GPL code and tried to hide it?

Yes but it can identify and block specifc application traffic. As Volker Birk keeps pointing out personal firewalls are something of a white elephant when it comes to security.

Yep, but if you didn't need the 4th port you could use about any solution and even cheaper ones.

You could setup a wireless router in your DMZ, have it issue IP's, and then have the user VPN into the LAN in order to get LAN access.

If you select an open-source solution you can have as many NIC's and subnets as you want, but it's not as simple to setup.

Maybe put your wireless unit on a Public IP, use WPA and Mac filtering, disable SSID broadcasting, and then have users PPTP into the network to use it - you would only need three ports with that.

Yes, I am aware of both legal problems and it does concern me on multiple levels. Had it not been for that I would probably have ordered one now - Russ being their best salesman. If it bothers me it is going to bother others and cause them business problems - so there is a lot of issues. Of course others may be "in line" for the patent issue but not the GPL issue.

So fortigate is in legal and perhaps business trouble. Netscreen is slow Sonicguard has poor support Cisco and checkpoint are overpriced and feature poor.

I would actualy go up a bit to the next level (EG Netscreen 25), but that seems to go to about tripple the price - just not worth it for me.

Now having done my research i'm going to have a drink.

The early FG50 is an obsolete product that was just too underpowered to keep up. I've pulled all the FG50's I installed, in favor of FG50A's. 2.8 code doesn't run on those oldies, and the 2.8 code is a vast improvement from 2.5 which is the code it did run. 3.0 will be a similar improvement. You can take an early low-end product failure and indict the entire product line if you want, I choose rather to enjoy the products they have now.

Yes, I'm aware. I think this will all blow over and be a minor footnote in a year or two. You can make your own choices. I'm currently installing more FG's than any other product line, and the people I'm putting them in for are simply thrilled at the results. IMHO, it just can't be beat for features and performance in the price bracket, right from the FG50A and FG60 up to the 3600 clusters I put in front of corporations and universities. Let the lawyers have their lawsuits. Lots of lawyers got rich off Microsoft too -- did you manage to excise all the Microsoft from your organization after they lost that suit?

-Russ.

Errmm minor technical difference - M$ have craploads of money, Fortinet don't. A half decent lawsuit will see them going down faster than the titanic.

No no reasonably good support with Sonicwall, Netscreen's has turned too crap (Junipers fault I believe).

I think you're best choices are either Sonicwall or Fortinet.

One last sales pitch, check out Sonicwalls Viewpoint reporting module compared to Fortinets, I "hear" Viewpoint wins hands down... but that is very second hand info and I've never seen the Fortinet equivilant so its worth checking yourself.

Your facts to back up your statements? They're a private company, not into publishing their financials.

-Russ.

To compare Viewpoint you would probably want to look at FortiReporter which is really just eIQ in disguise.

formatting link
Most of my clients are fine with the built in log viewers, those using category filtering like the ForiReporter product.

-Russ.

What you need my friend is to look at the Sidewinder G2 Application layer Firewall. The G2 Can handle up to a Million Plus connections.

It will block all application unless YOU allow it.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required