Which enterprise firewall to go for?

Gtx Gaming

Gtx Gaming
Joined
Aug 25, 2008
Messages
27,637
Reaction score
9,294
Location
cape town
We require an firewall with site to site vpn support now, so the untangle box is not going to cut it anymore.

Supplier quoted me the following.

XGS 2100 SECURITY APPLIANCE - EU/UK POWER CORD
XSTREAM PROTECTION FOR XGS 2100 12MONTHS

Total Coming 74k, I can't pay that just to have site to site vpn.

Any other suggestions? I know mikrotik is cheap a but the GUI is not great :(
 
Have you tried to set up an IPSec tunnel with your untangle setup?
 
We require an firewall with site to site vpn support now, so the untangle box is not going to cut it anymore.

Supplier quoted me the following.

XGS 2100 SECURITY APPLIANCE - EU/UK POWER CORD
XSTREAM PROTECTION FOR XGS 2100 12MONTHS

Total Coming 74k, I can't pay that just to have site to site vpn.

Any other suggestions? I know mikrotik is cheap a but the GUI is not great :(
XGS2100 just for an IPSec?
I mean what are the other requirements for the firewall?
What is the user count onsite?

I mean the You could away with a much smaller XGS depending on your needs.
 
XGS2100 just for an IPSec?
I mean what are the other requirements for the firewall?
What is the user count onsite?

I mean the You could away with a much smaller XGS depending on your needs.
We have 30 users on site maybe less most of the time atm, about 10 vpn users and then we will adding 2xipsec tunnels.
 
We require an firewall with site to site vpn support now, so the untangle box is not going to cut it anymore.

Supplier quoted me the following.

XGS 2100 SECURITY APPLIANCE - EU/UK POWER CORD
XSTREAM PROTECTION FOR XGS 2100 12MONTHS

Total Coming 74k, I can't pay that just to have site to site vpn.

Any other suggestions? I know mikrotik is cheap a but the GUI is not great :(
You can try AN Fortigate setup. But might be expensive.

Mikrotik is A cheap yes, but the interface is not that bad. Where is your other site going to be?
 
You can try AN Fortigate setup. But might be expensive.

Mikrotik is A cheap yes, but the interface is not that bad. Where is your other site going to be?
Other site will be in the UK and maybe other EU locations.
Luckily our cpt office is inside a datacentre so speeds are pretty quick.
 
That seems excessively expensive.
What size is the link, what other UTM features are you going to run?
Do you need to do any dynamic routing and if so, any idea on the amount of routes?

Also keep in mind a firewall should never be a standalone isolated purchase. It should tie into your security portfolio and compliment other security products.
It is very common to have a firewall and endpoint protection share information and dynamically provide protection mechanisms and enrich monitoring and reporting.
It should tie into your directory structures and participate in zero trust if possible
It should be providing some form of SD-WAN or at least some advanced link monitoring and application steering
There should be a decent threat intelligence feed.

None of this has to be particularly expensive if your solution is specd correctly and all portions are understood
 
That seems excessively expensive.
What size is the link, what other UTM features are you going to run?
Do you need to do any dynamic routing and if so, any idea on the amount of routes?

Also keep in mind a firewall should never be a standalone isolated purchase. It should tie into your security portfolio and compliment other security products.
It is very common to have a firewall and endpoint protection share information and dynamically provide protection mechanisms and enrich monitoring and reporting.
It should tie into your directory structures and participate in zero trust if possible
It should be providing some form of SD-WAN or at least some advanced link monitoring and application steering
There should be a decent threat intelligence feed.

None of this has to be particularly expensive if your solution is specd correctly and all portions are understood
Don't have that info was given basically nothing, all I know is staff member must be able to access client network from our office. They have cisco router on that side.

Luckily I have just 1 firewall and 1 server on-prem rest is all in azure.

Boss just said get it done, for cheaply :P
 
We require an firewall with site to site vpn support now, so the untangle box is not going to cut it anymore.

Supplier quoted me the following.

XGS 2100 SECURITY APPLIANCE - EU/UK POWER CORD
XSTREAM PROTECTION FOR XGS 2100 12MONTHS

Total Coming 74k, I can't pay that just to have site to site vpn.

Any other suggestions? I know mikrotik is cheap a but the GUI is not great :(

fortigate.Just select the right model for the size of company.Your sme models range from the forti 40 to the 100F.
 
  • Like
Reactions: OCP
Yes hardly every get used just uat server.
also remmember to spec your firewall based on the traffic throughput.Since most of your servers are in the cloud i would assume you demand a fast internet connection.Dont let your cheapie firewall throttle the throught.Check the firewall specs ie ,

SSL-VPN Throughput in Mbps/Gbps
Firewall Throughput in Mbps/Gbps
IPS throught in Mbps/Gbps
 
The real benefit of Fortigate or Sophos UTM devices to me is more around the application filtering,content filtering and that sort of thing or if you want to buy into their larger ecosystem. If you upgrade to paid Untangle, you're probably at Fortigate/Sophos money last time I looked.

If you need free or cheap site to site VPN you have options and you can run a separate VPN server behind your existing firewall.

Open Source VPN Server (VM, PI, PC, Whatever depending on your budget and performance requirements:
  • OpenVPN - the traditionalist
  • SoftEther - very good, multiprotocol including IPSec so nice if you need to connect to an IPSec Device on the other side
  • Wireguard - new kid on the block. Fast, Secure, does what it says on the tin
Devices:
  • Mikrotik - even a small one will probably handle 30 users or so site to site over IPSec or SSL VPN
  • OPNSense or PFSense
Mesh VPNs/global overlay networks:
  • Zerotier - cost effective for low number of nodes. OPNSense has a plugin I think to bridge to a LAN
  • Nebula - From Slack. Very nice. Not very developed in terms of management tools for the system.
  • Tailscale - Looks nice. Gets pricey for a large number of nodes
 
If you go Mikrotik, make sure to get one that supports hw acceleration for IPsec.
 
Top
Sign up to the MyBroadband newsletter
X