InTheCube
Expert Member
So our company has been using the iShield firewall appliance from local company Tradepage. Support is decent, pricing is reasonable, but the actual firewall software is not that great, and has many limitations.
I am looking for a similar firewall solution to the iShield, which is backed up with good support, and doesn't have the limitations listed below:
I am not looking to do it myself. I don't want to download, configure and manage a Linux distro. I need a solution that just works, and is from a company with good technical support.
I am looking for a similar firewall solution to the iShield, which is backed up with good support, and doesn't have the limitations listed below:
- You cannot block specific sites that make use of HTTPS. I can either block HTTPS completely for a single user, or allow it completely. I cannot block Facebook on HTTPS, but still allow FNB on HTTPS, unless I do it by IP address. This is a huge PITA. All the guys who need access to banking, and secure online services, also have access to Facebook, Twitter, Youtube, and any other service that encrypts its traffic.
Of course, one can block HTTPS to a particular IP address, but do services like Youtube, Facebook and Twitter have a fixed range of IP addresses that can be blocked? Are these websites not often served via CDN nodes, who probably change things around every now and then. Surely there is a way to simply block HTTPS to a specified domain names?
- When assigning static IP addresses to MAC addresses inside the DHCP server, you cannot specify what that static IP should be. The system will only allow you to assign the current DHCP-assigned address as static. So now we have statically assigned addresses littered accross our DHCP range. Not a train-smash, everything still works, but its a huge annoyance. I prefer having static addresses (even DHCP-assigned static addreses) in their own range. It also makes applying firewall rules to a group of users easier. We put them in the same range, and apply the firewall rule to this particular IP sub-range.
- The DHCP server cannot be easily configured to dish out a WINS server address. I cannot do this myself through the user interface. It has to be done behind the scenes by tech support.
- We are utilising a 3G connection as failover, for when our ADSL line goes down. There is also supposed to be email notification sent to the admin, to notify of the failover, and the fallback to ADSL (when it happens). However, the failover notification email never comes through. Only once the system falls back to ADSL, do both the failover and fallback notifications come. By this time it is too late to investigate what is going on.
I am not looking to do it myself. I don't want to download, configure and manage a Linux distro. I need a solution that just works, and is from a company with good technical support.
Last edited: