Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

replace my firewall with?

Status
Not open for further replies.
Dec 16, 2005
274
GB
I currently have 4 watchguard firewalls - 2 HA pairs (x1250e & x750e - running fireware pro 8.3)

I would like to replace them.

These firewalls do have all the functionally i require, if you are looking at a spec, but the mutli tunnel, mulit rule VPNs aren't stable and interminatly stop routing traffic. Also the firewalls fail over for no reason and do not always made over the multi tunnel VPN's.

Mutli tunnel, multi rule mutil driectional VPN's are not always possible to create exactly how you want them and comprimise must be made.

The remote mobile user vpn does not allow for multi rule to my mulitple internal networks in spilt tunnel config.

VPN Comaptablity with Cisco is near to not existant.

internal traffic crossing from one interface to another can be very slow at times.

Please can some one sugguest a replcaement firewall with-

-Stable branch office VPN (to non simlair devices, other companies)

-Mulit rule multi tunnel VPNs

-HA configuration

-multiple interfaces

-remote ipsec vpn for laptop users

-option for web filtering

-pre-defined rules

-no reboot on config changes.

-everything is denied by default

-auto block dos attacks

-able to change mtu on external interface

-external interface failover option

-auto ordering of rule processing

-able to re-key / reboot one VPN

-1-1 nat, snat dnat

-backup config and reload easily

-I hate restrcited wizards i want the option to create VPN's manually on a gui








 
Check into the Cisco ASA 5500 series. They have ASDM, a sophisticated GUI tool, that the most basic users could use to configure. I highly recommend these.

Burt
 
Take a look at Sonicwall Pro series. They do all you have asked for, and offer a web based interface to configure. There are wizards or you can choose to do it yourself.
 
I am not a fan of Sonicwalls. Sure they are okay for soho or small office their performance sucks in corporate space.
 
You might like to look at upgrading the fireware to a more recent version (Currently 10.02) Both versions 9 and 10 have included significant enhancements , notably policy based routing , which may offer what you require.Also the way in which BOVPNs are handled is much clearer now in Policy Manager.

Worth a try before embarking on a significant investment of money and time possibly ?



 
Thank you.

The asa 5500 series are there issues with VPN compatablity?

I know there are issues with asa 's and watchguard vpn. Is this only watchguard?


What do people think of checkpoint?

After failing to up grade my watchguard. I have had two experpts in to upgrade my watchguards and both have been unsuccesful. - ALl VPN's and NAT rules failed.

I know i could maunallly rebuild my ploicy instead of converting it and that may work. But if i'm going to do all that work it might as well be on a firewall that is stable.

Honstly had enough of all the work arounds to the many problems with watchguard
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top