Hardware Firewall

variance75

Junior Member
Dec 29, 2003
6
0
0
Hi All,

I run an internet cafe and decided to get a hardware firewall solution. Does anyone have any recommendation on the hardware for a firewall? Also do I have to use NAT in a hardware solution? I rather keep my statics IP and just block ports by IP.

Thanks in advance.

 

exx1976

Member
Nov 13, 2003
77
0
0
Depending upon the number of stations you have, I'd look into a Symantec VelociRaptor. It's a 1U box that can be had for ~$800 for a 40 node license. You can block anything by anything.. You can allow certain IPs to have free reign, certain IPs to only have port 80, etc, whatever you want. VERY nice unit, and very secure. For a couple hundred more, you can have VPN capability when you can VPN in from outside if you so desire.. I think they have a unit that also does caching (speeds up browsing and cuts down on traffic). I personally can't stand Symantec products, but their firewall line wasn't developed by them, they bought Eagle (used to make Raptor firewalls), which was a REALLY solid company... That's what I have here at my office (software solution, Enterprise Firewall, runs on Solaris).

It also does reverse NAT to map in HTTP traffic to an in-house web-server, or email server, or whatever... Quake server maybe.. LOL
 

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
GO with a Snapgear SME 550 @ $375 delivered. 5o0 Crypto Xlerated VPN tunnels, 35mb firewall thruput (15 mbps or so for 3DES), unlimted users (no licensing), free firmware updates for live. HTTPS/SSH admin access, dial in (thru phoneline) access to it, basic traffic Shaping, Can run it in bridged mode (like you want), asks as a DNS proxy, NTP server, ful CLI access, GUI. Linux imbedded on a chip. CAN NOT be beat for the price. Does all you need and MUCH more!
www.snapgear.com

SME 550
 

variance75

Junior Member
Dec 29, 2003
6
0
0
Snapgear looks good. Price looks even better. Bridge mode means no NAT? Install pretty easy? I crimped and developed the whole network infrastructure for the cafe but I am no network engineer.


Basically, I want to shut all all ports but 80, and a few game ports to the outside. Also can I limit bandwidth by IP? Sorry for all the questions. If you need to set up a Counter-Strike server I can help .


 

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
Out of curioisty, why are you interested in limiting bandwidth by IP? MIght not be able to do that with this.
 

variance75

Junior Member
Dec 29, 2003
6
0
0
Only have a T1 for 25 Machines. If someone decides to DL 100MB file. Everyone's latency goes hell. Since we run some game servers people playing from home don't like it either.
 

groovin

Senior member
Jul 24, 2001
857
0
0
i didnt know internet cafes allowed peopel to download large files like that. do you have ethernet ports for laptop users to jack into or something?
 

variance75

Junior Member
Dec 29, 2003
6
0
0
You are not really allowed to but its tough to monitor. So the best option is to limit the bandwidth so you wont.
 

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
Originally posted by: cmetz
OpenBSD on a PC...

Unfortunatey, not all of us (especially myself included) are *nix gurus, able to easily admin it compared to an appliance

Something to def. work with in lab or home to learn (as I am going to), and it is VERY powerful way to go, but tough in real world enviro when it isn't easily admin'd.





 

groovin

Senior member
Jul 24, 2001
857
0
0
pf is the firewall package that comes with openbsd and altq is a queing program... they integrate really well with each other. openbsd is free and VERY powerful but for people new to *nix, itll be tough to pick up in the begining.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |