ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    SMB firewall options

    IT Discussion
    16
    57
    8.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • gjacobseG
      gjacobse @zuphzuph
      last edited by

      @zuphzuph said in SMB firewall options:

      Untangle. 😄

      There was a time that I would have suggested UT,.. and I have used it at two Non Profits without any issues.

      @scottalanmiller has pointed me at laying off the UT bus and point more towards they true FW and I have installed a UBNT ERLite at home now. I've not spent a lot of time with it,.. but when my exposure with it in the Client field, the ER and ERL line work well.

      And as mentioned - OpenVPN is on nearly everything. Even the ER line.

      1 Reply Last reply Reply Quote 0
      • JaredBuschJ
        JaredBusch
        last edited by

        Untangle is fine if you want a massive AIO beast. I hate those though.

        zuphzuphZ 1 Reply Last reply Reply Quote 1
        • stacksofplatesS
          stacksofplates @JaredBusch
          last edited by

          @JaredBusch said in SMB firewall options:

          go with EdgeMax as a baseline

          EdgeRouter X?

          JaredBuschJ 1 Reply Last reply Reply Quote 0
          • zuphzuphZ
            zuphzuph Banned @JaredBusch
            last edited by

            @JaredBusch said in SMB firewall options:

            Untangle is fine if you want a massive AIO beast. I hate those though.

            Just out of curiosity, why?

            JaredBuschJ 1 Reply Last reply Reply Quote 0
            • JaredBuschJ
              JaredBusch @zuphzuph
              last edited by JaredBusch

              @zuphzuph said in SMB firewall options:

              @JaredBusch said in SMB firewall options:

              Untangle is fine if you want a massive AIO beast. I hate those though.

              Just out of curiosity, why?

              AIO are just bad in general.

              If you have 4 tasks that you need to do, separate them out unless there is a good benefit to keeping them AIO.

              1 Reply Last reply Reply Quote 1
              • JaredBuschJ
                JaredBusch @stacksofplates
                last edited by

                @stacksofplates said in SMB firewall options:

                @JaredBusch said in SMB firewall options:

                go with EdgeMax as a baseline

                EdgeRouter X?

                I would never use an ER-X for an office with more than 5 or 6 users. The ER-X does not have the balls for it.

                It is a great SOHO device.and handles that task well. For an office, I would always start with the ERL or ERPoE. Then move up to the ER-8 if needed.

                stacksofplatesS 1 Reply Last reply Reply Quote 4
                • stacksofplatesS
                  stacksofplates @JaredBusch
                  last edited by

                  @JaredBusch said in SMB firewall options:

                  @stacksofplates said in SMB firewall options:

                  @JaredBusch said in SMB firewall options:

                  go with EdgeMax as a baseline

                  EdgeRouter X?

                  I would never use an ER-X for an office with more than 5 or 6 users. The ER-X does not have the balls for it.

                  It is a great SOHO device.and handles that task well. For an office, I would always start with the ERL or ERPoE. Then move up to the ER-8 if needed.

                  I misunderstood what you were saying. I thought you were staying a certain model of theirs but you just meant the line with EdgeMax.

                  1 Reply Last reply Reply Quote 0
                  • wrx7mW
                    wrx7m @scottalanmiller
                    last edited by

                    @scottalanmiller said in SMB firewall options:

                    Only things I use anymore...

                    • Ubiquit for nearly everything.
                    • Sophos if they demand UTM but don't have the resources for the good stuff.
                    • Palo Alto if they really need edge security.

                    What would you consider "the good stuff" that you would use instead of Sophos UTM?

                    JaredBuschJ 1 Reply Last reply Reply Quote 0
                    • JaredBuschJ
                      JaredBusch @wrx7m
                      last edited by

                      @wrx7m said in SMB firewall options:

                      @scottalanmiller said in SMB firewall options:

                      Only things I use anymore...

                      • Ubiquit for nearly everything.
                      • Sophos if they demand UTM but don't have the resources for the good stuff.
                      • Palo Alto if they really need edge security.

                      What would you consider "the good stuff" that you would use instead of Sophos UTM?

                      Why do you mean? There are many pieces to an UTM.

                      The FOSS pieces are readily available individually.

                      wrx7mW 1 Reply Last reply Reply Quote 2
                      • V
                        Veet
                        last edited by

                        I think, for ~20 users, most of what you've listed would work (Although, I'm not a big fan of Cisco, and Watchguard)

                        Apart from DNS services, I haven't used any Cloud based security service...

                        1 Reply Last reply Reply Quote 0
                        • wrx7mW
                          wrx7m @JaredBusch
                          last edited by

                          @JaredBusch said in SMB firewall options:

                          @wrx7m said in SMB firewall options:

                          @scottalanmiller said in SMB firewall options:

                          Only things I use anymore...

                          • Ubiquit for nearly everything.
                          • Sophos if they demand UTM but don't have the resources for the good stuff.
                          • Palo Alto if they really need edge security.

                          What would you consider "the good stuff" that you would use instead of Sophos UTM?

                          Why do you mean? There are many pieces to an UTM.

                          The FOSS pieces are readily available individually.

                          I understand that there are many pieces to a UTM. That is why I am asking what, specifically, SAM considers the good stuff? The good stuff could mean brand, technology type or both.

                          J scottalanmillerS 2 Replies Last reply Reply Quote 0
                          • J
                            Jason Banned @wrx7m
                            last edited by Jason

                            @wrx7m said in SMB firewall options:

                            I understand that there are many pieces to a UTM. That is why I am asking what, specifically, SAM considers the good stuff? The good stuff could mean brand, technology type or both.

                            Juniper, WatchGuard, Checkpoint are usually considered the top contenders in UTM market...

                            but be prepared say a Junpier SRX5600 base model starts at $30,000.

                            Some of the check point models start at $150,000.

                            Watchguard is on the lowerend and I think their most expensive unit is only $50,000.

                            V 1 Reply Last reply Reply Quote 1
                            • V
                              Veet @Jason
                              last edited by Veet

                              @Jason said in SMB firewall options:

                              @wrx7m said in SMB firewall options:

                              I understand that there are many pieces to a UTM. That is why I am asking what, specifically, SAM considers the good stuff? The good stuff could mean brand, technology type or both.

                              Juniper, WatchGuard, Checkpoint are usually considered the top contenders in UTM market...

                              but be prepared say a Junpier SRX5600 base model starts at $30,000.

                              Some of the check point models start at $150,000.

                              Watchguard is on the lowerend and I think their most expensive unit is only $50,000.

                              I've used/deployed quite a few(This was years ago) Whatchguard appliances, and I really hated the interface and more so, the support .. Wouldn't rate them as "Top Contender" ... Checkpoint & Juniper - Yes ...But, these are for Enterprise level ...

                              For 20 users or so, I'd stick with an all-in-one box (UTM) ... Sophos, Sonicwall, pfsense ... all would work, just as well

                              Say, anyone heard of worked with Crossbeam, in the past ... ? I don't think the brand/company exists anymore ... but just wondering ..

                              scottalanmillerS J 2 Replies Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @wrx7m
                                last edited by

                                @wrx7m said in SMB firewall options:

                                @JaredBusch said in SMB firewall options:

                                @wrx7m said in SMB firewall options:

                                @scottalanmiller said in SMB firewall options:

                                Only things I use anymore...

                                • Ubiquit for nearly everything.
                                • Sophos if they demand UTM but don't have the resources for the good stuff.
                                • Palo Alto if they really need edge security.

                                What would you consider "the good stuff" that you would use instead of Sophos UTM?

                                Why do you mean? There are many pieces to an UTM.

                                The FOSS pieces are readily available individually.

                                I understand that there are many pieces to a UTM. That is why I am asking what, specifically, SAM considers the good stuff? The good stuff could mean brand, technology type or both.

                                Sorry, been away. "Good stuff" was referring to Palo Alto there.

                                J 1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @Veet
                                  last edited by

                                  @Veet said in SMB firewall options:

                                  For 20 users or so, I'd stick with an all-in-one box (UTM) ... Sophos, Sonicwall, pfsense ... all would work, just as well

                                  We've had bad luck with SonicWall. Unrealible, breaks things, hard to manage. If you are considering SonicWall, get Sophos instead.

                                  V 1 Reply Last reply Reply Quote 0
                                  • J
                                    Jason Banned @Veet
                                    last edited by

                                    @Veet said in SMB firewall options:

                                    For 20 users or so, I'd stick with an all-in-one box (UTM) ... Sophos, Sonicwall, pfsense ... all would work, just as well

                                    Sonicwall is crap.

                                    Pfsense is not really a UTM, it's a firewall sure you can add some packages to it but it doesn't perform that well as a UTM.

                                    scottalanmillerS 1 Reply Last reply Reply Quote 1
                                    • J
                                      Jason Banned @scottalanmiller
                                      last edited by

                                      @scottalanmiller said in SMB firewall options:
                                      and, technology type or both.

                                      Sorry, been away. "Good stuff" was referring to Palo Alto there.

                                      Palo Alto does not make true UTMs they are all considered firewalls. We have them and they are great but they aren't classified as UTMs.

                                      This is what Palo Alto themselves say about UTMs

                                      The only value proposition a UTM provides is to collapse the traditional (broken) network security infrastructure into a single box as a cost savings mechanism.

                                      scottalanmillerS 1 Reply Last reply Reply Quote 1
                                      • scottalanmillerS
                                        scottalanmiller @Jason
                                        last edited by

                                        @Jason said in SMB firewall options:

                                        @Veet said in SMB firewall options:

                                        For 20 users or so, I'd stick with an all-in-one box (UTM) ... Sophos, Sonicwall, pfsense ... all would work, just as well

                                        Sonicwall is crap.

                                        Pfsense is not really a UTM, it's a firewall sure you can add some packages to it but it doesn't perform that well as a UTM.

                                        And isn't meant to, it's meant to be a strong firewall / router. The thing that makes it so good is the incredible performance of the FreeBSD network stack and the pf firewall component of that. The other stuff is just random add-ons, generally not a good thing on a router.

                                        1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller @Jason
                                          last edited by

                                          @Jason said in SMB firewall options:

                                          @scottalanmiller said in SMB firewall options:
                                          and, technology type or both.

                                          Sorry, been away. "Good stuff" was referring to Palo Alto there.

                                          Palo Alto does not make true UTMs they are all considered firewalls. We have them and they are great but they aren't classified as UTMs.

                                          This is what Palo Alto themselves say about UTMs

                                          The only value proposition a UTM provides is to collapse the traditional (broken) network security infrastructure into a single box as a cost savings mechanism.

                                          Partly why I like PA so much 🙂 But they do more than a traditional firewall, less then a "full" UTM.

                                          BRRABillB 1 Reply Last reply Reply Quote 0
                                          • BRRABillB
                                            BRRABill @scottalanmiller
                                            last edited by

                                            @scottalanmiller said

                                            Partly why I like PA so much 🙂 But they do more than a traditional firewall, less then a "full" UTM.

                                            BTW, at MC you mentioned $10K as an entry point to PA.

                                            We have the PA-200 and it was less than $3K.

                                            And like $1.2K ongoing a year for subscriptions, support, etc..

                                            J scottalanmillerS DashrenderD 3 Replies Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 3
                                            • 2 / 3
                                            • First post
                                              Last post