Re: Moving from IPTABLES to SonicWall



Alex Molochnikov wrote:

We are contemplating a move from the IPTABLES firewall to a firmware-based
one. I've never used SonicWall (the proposed replacement). Could anyone tell
me if this is an adequate substitute for the Linux-based f/w?

What sonicwall model? IME, all the "TZ" models (tz 150, tz 170) have issues every time there is a new major firmware release. My 4060 on the otherhand has been rock solid. The saying "you get what you pay for" applies.


Currently, our small LAN (under 10 computers) is protected by a Linux
machine with IPTABLES that is used to route incoming connections from
trusted IP addresses to a host runnig a Java-based server. Some of the
connections are directed to other hosts, based on the destination port
number. Incoming connections occur on ports 80 (Web server), 422 (SSL), 1099
(RMI registry), and a variety of other ports (the external IP address of the
firewall is static). There is also some NAT involved.

All this is scripted in the IPTABLES rules, and I wonder if the
firmware-based firewall/router will be capable of providing similar
functionality.

Yes. Easily. That's like asking a professional concert pianist if he is proficient enough to be able to play chopsticks.

The enhanced OS boxes (don't get the "standard" OS if you can afford the enhanced) will do plain old NAT by address and by port (nat to completely different IP depending on port), bi-directional NAT, etc. Pretty much any NAT scenario you can think of.

Also available are snort like IPS, anti-virus at the gateway level, and the ability to integrate with web content filtering solutions.



Your advice will be greatly appreciated.

Thank you.
Alex.



.



Relevant Pages

  • Re: ISPs can easily decrease net abuse
    ... |use NAT with forwarding? ... When one of the inside systems wants to go out, the NAT device has to ... address to as it sends out the packets. ... Suppose the NAT box allocates port ...
    (comp.security.misc)
  • Re: How did they get past my NAT?
    ... network), I get no response, because there is no "Default host" set up ... behind my NAT, and no port forwarding for that port - if an explicit ... as I understand?), and not forwarded on the router, so there should be ...
    (comp.security.firewalls)
  • Re: firewall test and NAT
    ... off Internet address is 192.168.0.xxx. ... Port probes are looking for any open Port, and if they don't find one, they move on to the next possible victim without ever responding with an ACK to the Server. ... SRC is my NAT router on my 1st Ethernet port ...
    (microsoft.public.windowsxp.general)
  • Re: Processs PreciseMail AntiSpam Gateway - any experience so far ?
    ... Client sending system ... >> ISP using dynamic NAT with port overloading. ... >> 10.11.12.1 is the clients real address and it opens a connection from its port ...
    (comp.os.vms)
  • Re: firewall test and NAT
    ... off Internet address is 192.168.0.xxx. ... Port probes are looking for any open Port, and if they don't find one, they move on to the next possible victim without ever responding with an ACK to the Server. ... SRC is my NAT router on my 1st Ethernet port ... "John John" sends a message to "ToddAndMargo", NAT forwards the message and remembers this, it "waits" for a reply from ToddAndMargo and when the reply arrives from ToddAndMargo NAT sends it to John John. ...
    (microsoft.public.windowsxp.general)