Re: [pfSense] Replacing CheckPoint Firewall-1 with pfSense

2011-11-25 Thread Fuchs, Martin
Hi ! It's meant as more than 500 ports ;-) Am 25.11.2011 um 14:51 schrieb "Ugo Bellavance" : > On 2011-11-23 23:43, Daniel Davis wrote: > >>> >>> We are thinking about running a redundant (CARP) setup with one pfSense >>> on our VMWare cluster, and one on a physical, separate machine. >> >> I

Re: [pfSense] Replacing CheckPoint Firewall-1 with pfSense

2011-11-25 Thread Ugo Bellavance
On 2011-11-23 23:43, Daniel Davis wrote: We are thinking about running a redundant (CARP) setup with one pfSense on our VMWare cluster, and one on a physical, separate machine. I would not recommend a hybrid physical/virtual CARP cluster as CARP is entirely network reliant. In a physical CAR

Re: [pfSense] Replacing CheckPoint Firewall-1 with pfSense

2011-11-24 Thread Ugo Bellavance
(Sorry for top-posting) Thanks all for all your comments! Ugo On 2011-11-23 13:34, Ugo Bellavance wrote: Hi, We're thinking about replacing our CheckPoint Firewall-1 by pfSense. We are using only those features on Firewall-1 (R65): - Security (default deny on everything) - NAT (inbound (for i

Re: [pfSense] Replacing CheckPoint Firewall-1 with pfSense

2011-11-24 Thread Seth Mos
On 23-11-2011 19:34, Ugo Bellavance wrote: > Hi, > > We're thinking about replacing our CheckPoint Firewall-1 by pfSense. We > are using only those features on Firewall-1 (R65): > > - Security (default deny on everything) Delete the LAN -> any rule on the LAN interface and you are good to go. T

Re: [pfSense] Replacing CheckPoint Firewall-1 with pfSense

2011-11-23 Thread Daniel Davis
> -Original Message- > From: list-boun...@lists.pfsense.org [mailto:list- > boun...@lists.pfsense.org] On Behalf Of Ugo Bellavance > Sent: Thursday, 24 November 2011 4:04 AM > To: list@lists.pfsense.org > Subject: [pfSense] Replacing CheckPoint Firewall-1 wi

Re: [pfSense] Replacing CheckPoint Firewall-1 with pfSense

2011-11-23 Thread Yehuda Katz
On Wed, Nov 23, 2011 at 1:34 PM, Ugo Bellavance wrote: > We're thinking about replacing our CheckPoint Firewall-1 by pfSense. We > are using only those features on Firewall-1 (R65): > Concerns: > 3- Backups. Are automated backups (of the config, at least) possible even > w/o a service contrac

Re: [pfSense] Replacing CheckPoint Firewall-1 with pfSense

2011-11-23 Thread Nathan Eisenberg
> Hi, > > We're thinking about replacing our CheckPoint Firewall-1 by pfSense. > We > are using only those features on Firewall-1 (R65): Based on your requirements, you'll be quite happy with PFSense. ___ List mailing list List@lists.pfsense.org http:

[pfSense] Replacing CheckPoint Firewall-1 with pfSense

2011-11-23 Thread Ugo Bellavance
Hi, We're thinking about replacing our CheckPoint Firewall-1 by pfSense. We are using only those features on Firewall-1 (R65): - Security (default deny on everything) - NAT (inbound (for internet-facing hosts) and outbound (selective, workstations go out through a proxy, other selected hosts