Thanks for the reply Sergio. After giving it some thought I did come to the same conclusion that the web filtering shouldn't be done on the UTM-1 for the reasons you pointed out. I was looking at the option to use the UTM-1 for web filtering because I needed to upgrade my Barracuda Web Firewall, I think I will continue down the path of upgrading it to continue handling the web filtering. The cost is probably close to the same or probably less then using the UTM-1 for web filtering anyway.
I will probably end up upgrading from my HP DL140 running SPLAT NGX R65 gateway to the UTM-1 572 or 1073 appliance with R70 to just handle Firewall and VPN as it is now. From: Sergio Alvarez <[email protected]> To: [email protected] Date: 03/07/2010 08:13 PM Subject: Re: [FW-1] UTM-1 R70 Software Blades Sent by: Mailing list for discussion of Firewall-1 <[email protected]> Hello, First of all, I wouldn't replace a dedicated web filtering device for ANY UTM url filtering feature. It is almost impossible to achieve the same level of granularity and robustness. Remember the main function of a UTM appliance is being a firewall, anything else are just extra features. If you need all the features but don't have enough money or space to get them in separate devices, get a UTM, otherwise let each device do what it was mainly design for. If you are happy with your Barracuda, my very personal opinion is: keep it. Now, in regards of Fortinet, they do offer UTM appliances at a very good price (pretty lower than CheckPoint), bad thing is, they offer things their appliances just can't do, so you might bump into very bad surprises if you invest on one of those boxes. We all know all vendors provide numbers in their datasheets that were taken from lab environments and very controlled situations, so those numbers are not achievable in real production networks, but Fortinet goes way beyond that and with no shame at all, lie awfully in their datasheets, you wouldn't believe the stories I've heard. Bare in mind this is just my humble opinion. Hopefully my comments will still be of use for you at this point. Regards On Fri, Feb 19, 2010 at 8:44 AM, John Lindblom <[email protected]> wrote: > I'm preparing for an upgrade from NGX R65 running SPLAT on a HP server to > possibly one of the UTM-1 appliances specifically the 1073/1076 for a 300 > user network. I'm currently using a Barracuda Web Filter for URL and > antivirus/anti -malware filtering that also need to be upgraded soon so > I'm considering the UTM options for this. > > I'm trying to determine if the web filter could be replaced with the URL > Software Blade and the Antivirus & Anti-Malware Software Blade. Anyone > have any experience yet with these blades? We are happy with the > Barracuda Web Filter but it is another piece of hardware, I'm being told > this can now be replaced and handled on the UTM appliance. It also > appears Fortinet is giving Checkpoint a strong run for the money with the > FortiGate UTM appliances, my vendor is recommending I take a serious look. > > Any feed back or real world experience with these Checkpoint UTM Software > Blades would be appreciated. > > John > > ------------------------ > The information contained in this email and any attachments may contain > confidential, proprietary, business sensitive, privileged or controlled > information. If you are not the intended recipient, any disclosure, > dissemination, distribution, duplication or other unauthorized use of the > information contained in this email or any attachment is strictly > prohibited. Unauthorized interception of this e-mail is a violation of > law. If you are not the intended recipient, please notify the sender by > reply email and immediately and permanently delete this mail and any > attachments and any copies of them. > > Technical data and/or information provided in this email or any attachment > may be subject to U.S. export control laws. Export, re-export, diversion > or disclosure contrary to U.S. law is prohibited. It is your > responsibility to check this email and any attachments for viruses or > other harmful code before opening or forwarding. > ------------------------ > > > Scanned by Check Point Total Security Gateway. > > ================================================= > To set vacation, Out-Of-Office, or away messages, > send an email to [email protected] > in the BODY of the email add: > set fw-1-mailinglist nomail > ================================================= > To unsubscribe from this mailing list, > please see the instructions at > http://www.checkpoint.com/services/mailing.html > ================================================= > If you have any questions on how to change your > subscription options, email > [email protected] > ================================================= > -- Sergio Alvarez +(506)88301342 Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] ================================================= ------------------------ The information contained in this email and any attachments may contain confidential, proprietary, business sensitive, privileged or controlled information. If you are not the intended recipient, any disclosure, dissemination, distribution, duplication or other unauthorized use of the information contained in this email or any attachment is strictly prohibited. Unauthorized interception of this e-mail is a violation of law. If you are not the intended recipient, please notify the sender by reply email and immediately and permanently delete this mail and any attachments and any copies of them. Technical data and/or information provided in this email or any attachment may be subject to U.S. export control laws. Export, re-export, diversion or disclosure contrary to U.S. law is prohibited. It is your responsibility to check this email and any attachments for viruses or other harmful code before opening or forwarding. ------------------------ Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] =================================================
