Re: [fw-wiz] Firewalls & multicast- what's the choice?



The PIX will also participate in mcast routing protocols. It can also
be configured to join a mcast group for systems that are unable to
send IGMP join requests; and relay the traffic out the proper
interface.

On 8/1/06, Carson Gaspar <carson@xxxxxxxxxx> wrote:
The only firewall I know of that actually speaks multicast routing is the
Juniper/Netscreen. Almost any firewall can be configured to forward the
traffic, but most won't participate in the group membership protocols.
Others have recommended the PIX - it would be my second choice, as it
handles heavy loads pretty well. Checkpoint would be dead last - it's
terrible at small packet high volume forwarding.

--On Tuesday, August 01, 2006 11:41 AM +0000 Bob Arthurs
<bob_arthurs@xxxxxxxxxxx> wrote:

hello

my company is going to build three new data centers and we are
considering what type of firewalls to put in. i need some advice, and
any help is very much appreciated...

The firewalls need to be able to forward quite high volumes of mulitcast
and interact with **PIM router** (cisco router). Traffic volumes are at
least 10s of Mbps (including unicast traffic), maybe 100s, maybe 1Gbps!

Previously we have used Nokia firewalls, but we want to know what people
are choosing thes days for data center/multicast:

should be go with Checkpoint, Cisco, other....

do we need Checkpoint Secure Platform / Secure Platform Pro?

do we need Checkpoint on Crossbeam or other appliance?

any special considerations for PIM / Multicast?

what are the alternatives, when are they used, and what are their
pros/cons.


Thankyou very much in advance....


_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



--

Pete Capelli pcapelli@xxxxxxxx
http://www.capelli.org PGP Key ID:0x829263B6
"Those who would give up essential liberty for temporary safety deserve neither
liberty nor safety" - Benjamin Franklin, 1759
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • VPN - Cisco PIX to Checkpoing FW-1 troubleshooting
    ... I was trying to establish VPN between a pix and a checkpoint. ... isakmp policy 10 authentication pre-share ...
    (comp.security.firewalls)
  • Re: Nokia and CheckPoint or Cisco?
    ... Currently use a Nokia IP330 box with CheckPoint on. ... Cisco PDM has a basic GUI for PIX. ... active/standby mode, except when PIX 7.x is configured using multiple ...
    (comp.security.firewalls)
  • RE: Firewall recommendations?
    ... I have run both Checkpoint and PIX in my environment. ... The PIX is a true stateful inspection firewall. ... I am not a big fan of the pix and I have never played with the ISA ...
    (Security-Basics)
  • RE: Firewall recommendations?
    ... Hi at my current job we use checkpoint, and I personally love that firewall ... I am not a big fan of the pix and I have never played with the ISA ...
    (Security-Basics)
  • Re: enterprise class firewalls - opinions please
    ... You've pretty much nailed the current market: ... It sounds like they're not developing the PIX ... Checkpoint - got complacent, in the last financial year they're the only ... > separate management stations for logging and fw management. ...
    (comp.security.firewalls)