RE: [Firewalls] Firewall choice for web hosting

From: Bill Lavalette (billl@cyberbase7.com)
Date: 07/24/02


From: "Bill Lavalette" <billl@cyberbase7.com>
Date: Wed, 24 Jul 2002 15:06:53 GMT

Dean -

Checkpoint Firewall/VPN-1 NG is far superior to Cisco in many ways, the fact
that it sits on top of a another OS is in my opinion irrelevant. Regardless
of firmware/OS you always have to maintain the vendor software. there are
many ways to defeat the OS conundrum. As with anything the machine is as
secure as the experience building it. if one takes their time to build a
hardened machine the amount of work maintaining would be the same as
firmware upgrades. Example we use a NT box C2 hardened been up for almost a
year with zero problems. Also if properly set up no one will be able to
connect to your firewall machine anyways. I think you will be impressed with
Check Point. One thing you might want to check out is their Secure Platform
a prehardened Linux OS. NG+Secure Platform Blows all the other firewall
vendors away performance/feature wise.

Hope this helps

Regards

Bill

Chief Security Officer
CyberBase7 Security Services METRO-SOC
Email:Operations@cyberbase7.com
WWW:http://www.cyberbase7.com

-----Original Message-----
From: firewalls-admin@section5.cyberbase7.com
[mailto:firewalls-admin@section5.cyberbase7.com]On Behalf Of Dean Smith
Sent: Wednesday, July 24, 2002 6:03 AM
To: firewalls@section5.cyberbase7.com
Subject: [Firewalls] Firewall choice for web hosting

I am looking into a new firewall choice for organisation I have just
joined which hosts a very large volume web site.

Normally I would use Cisco PIX products, a choice based somewhat on my
familiarity with Cisco kit and their good security record, but this
has been in situations where I also needed to send outbound corporate
traffic out through the same network. The PIX has a few niggles, such
as the alias command and PDM, that make the hosting part slightly more
difficult than needs be.

For a hosting only solution I am wondering if there is a better
solution, Firewall-1 being my current second choice.

I would be interested in peoples thoughts of this, especially in terms
of stabailty, security and ease of management for web hosting. One
concern I have with FW-1 is that it runs on top of another OS and
flaws int he OS may expose the firewall to attack. Does the Nokia FW-1
product suffer from this short coming ?

Thanks

Dean Smith
_______________________________________________
Firewalls mailing list
Firewalls@section5.cyberbase7.com
http://section5.cyberbase7.com/mailman/listinfo/firewalls



Relevant Pages

  • Re: [fw-wiz] Cisco 2811 vs. ASA 55xx
    ... Cisco ASA units are the replacements/upgrades for the PIX. ... "Is the lack of flexibility of the ASA justified by the higher performance? ... I'm not real sure what you're trying to do security-wise with a Cisco router that a Cisco firewall appliance cannot do. ...
    (Firewall-Wizards)
  • Re: Firewall Hardware and a bit of a Rant
    ... I need advice on which hardware firewall to purchase for a client with 20 users. ... I'm fairly new to SBS and have installed 3 servers. ... Watchguard seem to think they are Cisco and don't have to provide support to smaller IT guys because they are so powerful etc.. ... If my client didn't need web filtering, I'd bang a PIX in and use the Cisco VPN Client for remote access with local database XAuth to provide double authentication. ...
    (microsoft.public.windows.server.sbs)
  • RE: Network IDS
    ... I'd say running the same OS for your firewall as your desktop machines ... Subject: Network IDS ... I'm using cisco products: Cisco Secure PIX firewall and Cisco Secure ... > Currently I have been looking at the Symantec Gateway Device. ...
    (Security-Basics)
  • Cisco PIX 515E vs. Fortinet Fortigate-300
    ... Firewall Evaluation ... Cisco PIX 515E vs. Fortinet Fortigate-300 ... Fortigate firewall. ...
    (comp.security.firewalls)
  • Re: ISA and Separating Networks
    ... > You need the switch to connect all the "outsides" together to the inside ... > of the cisco router. ... > firewall and SBS) will be using a private IP range, ...
    (microsoft.public.backoffice.smallbiz2000)

Quantcast