Yes.
There are a few real differences between the PIX and Check Point that make
each unique in what it can do. Of course, given the choice of only one, I'd
choose FW-1, but the model you are describing is the best-of-breed
infrastructure model you can have.
* The PIX is fast. Hardware based, so attacks such as DoS and DDoS are less
of an impact if they make it past your router ACL. Public web severs are
also
perfect for its DMZ for speed.
* The PIX is less complex. It does a few things, and it does them well. One
or two DMZ's is perfect, anymore gets out of control.
* The PIX can have changes made to it very quickly. This makes it much
easier to put in a temporary block for an out of control INet attack. You
can also add new servers quickly if need.
* The PIX has better support. Sorry, but Cisco just beats Check Point by
TONS in this dept. They can't touch Cisco. This usually means you can at
LEAST have your Public web servers and Internet traffic flowing if there is
a disaster with the CP and/or PIX (wrong policy install, hardware down, etc
etc)
* FW-1 can handle VERY complex scenarios. Many DMZ's, complex NAT, etc,
This is what makes it hands down the best choice for a sole firewall.
* FW-1 can be run on all kinds of hardware, which means scaling it can be
very cost-effective.
* FW-1 has some features the PIX can't even come CLOSE to touching:
Logging, for one.
* FW-1 has awesome support for add-in OPSec third party applications.
There are more,
To answer your question, I'd use the above strengths to make your design.
Make the PIX do what it is best at. Make the CP do what it is best at.
Regards,
Matt Goddard
Security Information Team
Schneider National, Inc.
"To find out what one is fitted to do and to secure an opportunity to do so
is the key to happiness."
|---------+-------------------------------------------->
| | [EMAIL PROTECTED] |
| | Sent by: Mailing list for |
| | discussion of Firewall-1 |
| | <[EMAIL PROTECTED]|
| | KPOINT.COM> |
| | |
| | |
| | 01/10/2005 06:58 AM |
| | Please respond to Mailing list |
| | for discussion of Firewall-1 |
|---------+-------------------------------------------->
>----------------------------------------------------------------------------------------------|
|
|
| To: [email protected]
|
| cc:
|
| Subject: [FW-1] "Checkpoint behind Cisco PIX" Design
|
>----------------------------------------------------------------------------------------------|
Dear all,
Happy New Year, full of health, successes and prosperity.
Has anybody implement the following design:
"Internet Router" --> Cisco PIX (with DMZ)--> Checkpoint Firewall(securing
Intranet)?
Any hints and details on this?
I checked both Cisco and Checkpoint but didn't find much.
Many thanks in advance,
Kostas
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================