What is the Best Fire Wall for and ISP?

inX

New Member
Joined
Dec 14, 2005
Messages
5
Reaction score
0
Can someone tell me what is the best Fire wall for an ISP?

Will it be the Sonicwall Products? We have tried it and do not seem to work well and cost a arm and a leg

Do any body know the Astaro Fire wall? Hear it is very good and stabile with Spam assistance

Or the AstroFlowGuard


Thanks
 
Last edited:
Depending on the Size of an ISP, a Cisco PIX Firewall right down to IPCOP.....
 
Better to start with a free firewall such as smoothwall or ipcop and see how things work before forking out lots of wonga for other firewalls (which may or may not work).

I had a look at Injoy Firewall, it is very, very complex, and I never managed to get it up and running. In contrast, Smoothwall (or Ipcop) is very simple, easy to set-up and maintain, and doesn't cost an arm and a leg.
 
Best ? IPTABLES

System requirements: Minimal - But linux / unix based
Technical requirements: Nominal
Learning curve: Depending on network knowledge, can be extreme.

IPTABLES is a set of tools to help you put together a customised firewall script. There are a lot of scripts available on the web already, or you can just write your own. In my experience this has been the most stable and customisable of all firewalls I have worked with. Easy to use as a SOHO or easy to scale up to corporate, load balancing type solutions.

http://www.netfilter.org
 
If you're an ISP (well, depending on your size I guess) - Go for something like Cisco PIX or Checkpoint Firewall-1.

You're looking at lots of moola tho.
 
Astroflow Guard is a excellent choice.Its made by a company called Netsoft from Durban.Its a customized version of Linux and running behind the pretty GUI is Iptables + Snort (intrusion Dectection) + many more things.Definetly i recommed it.
 
If you are looking for something powerful and free have a look at pfsense, its built on freebsd 6.0 and its really impressive. It does however require some brains to operate so be prepared.
 
cisco pix is good but checkpoint firewall i s better and more stable
 
If youre an ISP youre going to want something commercially supported.
I say this for if you are using a freebie then unless you have intricate knowledge of the system you will be faced with a large learning curve.
Associated with your learning curve will be a period during which youre firewall will not be protecting you properly. If you lose youre firewall youre out of business, so a support contract with product specialists is necessary incase of failure.

Many small businesses can get by on a linux vartiant solution.
They can even pay small money and use a MS box with routing and remote access.
Then you can look at the other cross platform solutions mentioned in this thread.
Then specialised devices ie: cisco pix 506 (small entry level fw) then branch up to a 515, then depending on your need go bigger.
When you reach the level of a PIX then another player is Checkpoint.

There are a lot of others, and i am generalising, but in the US and Europe the PIX and Checkpoint are the top players.
Theyre regarded as such due to the quick patching of holes, comprehensive support contracts and built in hardening of the OS.

I head up Security for a major player, so PM me if you need more advise
or check out security websites - they will give you expert opinion.
 
PIX :) As long as you set it up properly that is... some twit on our side set it up originally to have the following rule:

Allow in: Any
Allow out: Any

10 points to the person who tells me what's wrong with that? :D
 
If you want a commerially supported linux firewall ( the best in my opinion ) then go for one of the mainstream distro's ( RedHat / Suse, etc ) and buy their support option.
 
Smoothwall.net offers commercial support withtheir commercial Smoothwall firewall. The Smoothwall.org is the free version.

The only difference between these two is that with the cheap option you'll have to do it yourself...
 
Top
Sign up to the MyBroadband newsletter
X