RE: Firewall recommendations?

From: David Ellis (dellis@unicam.com)
Date: 03/08/03

  • Next message: Scott Borre: "sniffing packets on a switch"
    From: David Ellis <dellis@unicam.com>
    To: "'Thorsten Dampf -- 7stein.net'" <thorsten.dampf@7stein.net>, "'rdusek@myway.com'" <rdusek@myway.com>, "'security-basics@securityfocus.com'" <security-basics@securityfocus.com>
    Date: Fri, 7 Mar 2003 21:05:03 -0500 
    
    

    Hi at my current job we use checkpoint, and I personally love that firewall
    product. I am not a big fan of the pix and I have never played with the ISA
    server cause it is a microsoft product and would not trust it. We are very
    security conscious company. I think checkpoint has the best interface
    around. But hey that's my personal opinion. The cisco pix is not a true
    stateful packet inspection firewall. I have a classified pdf that talk about
    the pix versus checkpoint in a situation with multiple exchange servers and
    the ports you had to allow open for the pix to work in the environment that
    was documented was totally unsafe.
    At my next job, I would suggest going with checkpoint. Its not that
    expensive when you start thinking about isa server cause You still need the
    hardware, the windows server OS license and then the ISA license.

    -----Original Message-----
    From: Thorsten Dampf -- 7stein.net [mailto:thorsten.dampf@7stein.net]
    Sent: Friday, March 07, 2003 3:48 PM
    To: rdusek@myway.com; security-basics@securityfocus.com
    Subject: AW: Firewall recommendations?

    Take a look at the watchguard products. www.watchguard.com

    Regards, Thorsten

    > -----Ursprüngliche Nachricht-----
    > Von: rdusek@myway.com [mailto:rdusek@myway.com]
    > Gesendet: Donnerstag, 6. März 2003 21:05
    > An: security-basics@securityfocus.com
    > Betreff: Firewall recommendations?
    >
    >
    >
    >
    > I am in charge of researching a firewall to replace what we currently
    >
    > have. At my previous job I had used Microsoft ISA in a low-security
    >
    > environment, and was happy with its features, and its
    > integration with
    >
    > the Windows environment there. However, at my current job,
    > security is a
    >
    > much greater concern, and I have to admit, I am somewhat
    > uneasy running a
    >
    > Microsoft firewall product on top of a Microsoft OS. We also had
    >
    > investigated Checkpoint as well as Cisco Pix, and found that for our
    >
    > needs, the Pix at least seemed to need _many_ separate
    > components for the
    >
    > same functionality. My question is what are your experiences
    > with using
    >
    > ISA from a security standpoint? Usability issues? From the
    > Mac end? Or
    >
    > would we be better off pursuing the Checkpoint or the Pix
    > solution? We
    >
    > also plan on implementing VPN over whatever we choose, so if you
    >
    > recommend something other than these, it should support at
    > least PPTP and
    >
    > perhaps eventually IPSec/L2TP. We have also considered placing ISA
    >
    > behind a Linux (or BSD) IP Chains firewall and our perimeter
    > network to
    >
    > block some of the traffic from getting to ISA. Any comments
    > here? Thanks
    >
    > to everybody in advance!
    >

    **************************************************************************************************
    ** eSafe-portsmouth scanned this email for viruses, vandals and malicious content **
    **************************************************************************************************


  • Next message: Scott Borre: "sniffing packets on a switch"

    Relevant Pages

    • Re: ISA Server versus Checkpoint Firewall
      ... Also, there is more to "stateful" than you describe; it goes all the way to L7, something Checkpoint doesn't yet do. ... Checkpoint is only recently starting to realize the value of application-layer filtering; something ISA has had for years. ... ISA Server can be fairly easy to just plug in, ... Unfortunately that can often be a bad thing as it is very easy to misconfigure a firewall and the ...
      (microsoft.public.isa.enterprise)
    • RE: Firewall recommendations?
      ... I have run both Checkpoint and PIX in my environment. ... The PIX is a true stateful inspection firewall. ... I am not a big fan of the pix and I have never played with the ISA ...
      (Security-Basics)
    • Re: Firewall recommendations?
      ... and you can say so does the PIX. ... checkpoint can be had as an appliance or you might want to install and configure ... its much easier to go with an appliance type firewall. ... Then you should consider your network requirementand your business requirements ...
      (Security-Basics)
    • Re: Is this ISA server setup right or wrong?
      ... > pix 501 and a vpn between the sites. ... > to implement an ISA server behind the pix firewall at the ... The remote VPN subnets (private IP ...
      (microsoft.public.isa)
    • Trying to set up VPN tunnel from SBS/ISA2004 to Checkpoint FW1
      ... I have just added ISA 2004 onto my SBS server from the Premium Edition SP1 ... I am looking at replacing my Checkpoint firewall with this, ... using Checkpoint I had a VPN tunnel set up between my network and one of my ... IKE security association negotiation failed. ...
      (microsoft.public.windows.server.sbs)