Firewalls and VPNs

EvanBlackwood

Member
Oct 14, 2000
42
0
0
Hey team,

Looking for some input. When it comes to enterprise wise security policies, what do you think is better, a software solution like Symantec Enterprise and Check Point Software, or a hardware solution, like Cisco? Just curious. If you have any input of middle-tier companies that might help as well. Thanks again!

Regards,

EB
 

FireDragon

Junior Member
Aug 2, 2001
6
0
0
well as most things it usually comes down to money... software is good and all... in fact I?m currently using checkpoint; however, I much prefer hardware security solution. remember when all else is equal, hardware is always faster (and usually better). actually, I prefer a combination of both hardware and software,it's all about layers!.

think about the hardware v. software issue this way. ok for software you have the software running on someone else's software i.e. the OS, that is running on someone else?s hardware. not to mention what ever else I running on that box, could present a different risk, say IIS for example. however hardware, it's plain simple, only the manufacture?s software running on it's hardware. not much to go wrong.

same holds true with routers and layer 3 switches etc... final example: NT supports RIP and OSPF, but do you know anyone that uses a NT box to route? probably not, because a $150 router dose a better faster job.

 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
which one is better?

They both have their strengths and weaknesses. In general a hardware device out performs software, especially wintel. Checkpoint is an awesome firewall, I've used if for a long time. Pix is an awesome firewall. They each have features the other one doesn't. Heck, I love the little nokia checkpoint appliances. cheap and easy.

Just FYI, I'm ripping out our 8 checkpoint firewalls and putting in some PIX. Too frustrated with checkpoint support and the underlying solaris OS. Our firewall configurations are very complex and get hard to manage when I have to control routing on Solaris with 8 interfaces and throw lots of VPN at it.

between the two...well the network answer is "it depends"
 

Garion

Platinum Member
Apr 23, 2001
2,328
6
81
Only catch with PIXes - Management sucks, unless it's gotten better in the last year or so.

The Nokia boxes are supposed to be excellent firewalls. They run checkpoint on a dedicated hardware platform. They were the first to provided gigabit throughput via a firewall. Might be worth checking out.

Skip the Symantec stuff. Checkpoint and Pixes are the dominant firewalls out there and are, by far, the most commonly used in the enterprise.

For a true enterprise security policy, why choose? To do it right you should have at least two layers of firewalls - Stick PIX out in front of your DMZ and directly connected to the internet. Pixes are rock solid and high performing and you don't need many rules out there. Between your DMZ and internal network put in a Nokia. Flexible to manage your outbound policies and very stable and secure. Much better security, as a hacker has to get through BOTH layers of security, something that's much more difficult to do than just one layer.

I work for a bank and we have, believe it or not, four layers of firewalls. Not my design, don't have to manage it, thank god..

Depends on your budget tho.. Can't go wrong with a Nokia running Checkpoint or just a Pix.

- G
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |