Re: all-in-one vs one-on-each (feat. Comercial vs FOSS)



On 2008-05-24 Alex wrote:
I would like some opinions, again.
For a fixed budget would you go for
* an all-in-one "Firewall" ( FW+IPS+VPN+...) ie. Checkpoint,
* a dedicated, known and expensive firewall/gateway with the company of
an Open Source solution for IPS, URL filtering etc?
* a full Open Source solution (iptables,snort,ossec,squid etc) and
spend the money elsewhere :)

The things that concern me are,

Redundancy. I can live without IPS for a while but not without Internet
( and by "I" I mean "The Company")
Scalability. Not only performance-wise but cost-wise too. I think that
having to pay for every "extra feature" is going to lead to Open Source
anyway...
Complexity. Better to manage one than more, right?...

The answer to your question depends heavily on the actual requirements,
your network topology, your admins' expertise, and what kind of "fixed
budget" you have.

Regards
Ansgar Wiechers
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq



Relevant Pages

  • Re: all-in-one vs one-on-each (feat. Comercial vs FOSS)
    ... commercial support if you so choose. ... an Open Source solution for IPS, ... I can live without IPS for a while but not without Internet ...
    (Security-Basics)
  • all-in-one vs one-on-each (feat. Comercial vs FOSS)
    ... I would like some opinions, ... an Open Source solution for IPS, ... I can live without IPS for a while but not without Internet ...
    (Security-Basics)
  • Re: all-in-one vs one-on-each (feat. Comercial vs FOSS)
    ... an Open Source solution for IPS, ... I don't think that Checkpoint SmartDefense is an adequate replacement for a decent IDS/IPS. ... if you have a pool of highly capable and willing IT professionals to help build it out, FOSS probably will end up being cheaper and better. ...
    (Security-Basics)
  • Re: [fw-wiz] State of security technology for the enterprise
    ... being concerned that if I architect an open source solution and leave, ... I've never seen that level of reluctance at any large enterprise I've worked ... years as the challengers to "stateful packet inspection" looked for their ...
    (Firewall-Wizards)
  • RE: any recommendable anti-ddos solution?
    ... HIPS solutions do support DDOS and other exploits. ... Are there any other open source HIPS/IPS ... How about enterprise management in the case of remote ... Wireless IPS solutions/scanners running at the ...
    (Security-Basics)