[swinog] Firewall recommendation for a rack of webservers?

2008-06-18 Thread Olivier Mueller
Hello, Now that the office firewall is running fine (uptime: 34 days, not a single problem since last month, cf. the "VDSL/Zyxel P2802 HWL not "strong" enough for a small company LAN?" thread), I'm now back, looking for a new kind of firewall :) For a specific project with it's own rack @datace

AW: [swinog] Firewall recommendation for a rack of webservers?

2008-06-18 Thread Michele Capobianco
Check out the Juniper Firewalls. Ok Price. Rackmountkit available. Scaleable form Small (office) to Enterprize. We use Juniper(Netscreen) sience 12 Years. -Ursprüngliche Nachricht- Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftrag von Olivier Mueller Gesendet: Mittwoch, 18. Juni

Re: [swinog] Firewall recommendation for a rack of webservers?

2008-06-18 Thread Rainer Duffner
Olivier Mueller schrieb: Hello, Now that the office firewall is running fine (uptime: 34 days, not a single problem since last month, cf. the "VDSL/Zyxel P2802 HWL not "strong" enough for a small company LAN?" thread), I'm now back, looking for a new kind of firewall :) Is there anything you

Re: [swinog] Firewall recommendation for a rack of webservers?

2008-06-18 Thread Beat Siegenthaler
Rainer Duffner wrote: http://pfsense.org/index.php?option=com_content&task=view&id=44&Itemid=50 and start with that. But the customer would also like to see some "non open-source"-based solutions... :> I'd go for a Netscreen model - The funny thing about this: Netscreen and pfSense are bo

Re: [swinog] Firewall recommendation for a rack of webservers?

2008-06-18 Thread Rainer Duffner
Beat Siegenthaler schrieb: Rainer Duffner wrote: http://pfsense.org/index.php?option=com_content&task=view&id=44&Itemid=50 and start with that. But the customer would also like to see some "non open-source"-based solutions... :> I'd go for a Netscreen model - The funny thing about this

Re: [swinog] Firewall recommendation for a rack of webservers?

2008-06-18 Thread Olivier Mueller
On Wed, 2008-06-18 at 15:38 +0200, Rainer Duffner wrote: > pfSense is FreeBSD6 ;-) and the next one will be FreeBSD 7 based, yes :) Thanks you all for the feedbacks on the list and by mail, I'll now have fun visiting all your suggestions / urls trying to select the "perfect" device. Merci & s

Re: [swinog] Firewall recommendation for a rack of webservers?

2008-06-18 Thread Chris Gravell
Can always go for Watchguard @ that price/performance point. watchguard.com -- From: "Rainer Duffner" <[EMAIL PROTECTED]> Sent: Wednesday, June 18, 2008 3:38 PM To: <[EMAIL PROTECTED]> Subject: Re: [swinog] Firewall recommendation for a rack of web

Re: [swinog] Firewall recommendation for a rack of webservers?

2008-06-18 Thread Rolf Sommerhalder
Looking at your specs, I personally would chose OpenBSD (http://openbsd.org) and commodity i386 or amd64 rack servers (check the hardware compatibility list to avoid nasty surprises). Besides a stateful packet filter "pf" functionality, OpenBSD comes with many tools to cluster those servers, such

Re: [swinog] Firewall recommendation for a rack of webservers?

2008-06-18 Thread Chris Gravell
Sounds like a lot of hard work, Rolf! BSD may be free but as you probably know, - the ongoing support costs are often the larger proportion of any network deployment. Not to mention that the base OS will probably require hardening too...expertise like that would quickly dwarf his budget unless it'

Re: [swinog] Firewall recommendation for a rack of webservers?

2008-06-18 Thread Rolf Sommerhalder
Chris Gravell wrote: > Sounds like a lot of hard work, Rolf! Yes, but it's fun as well as, as you can really learn and understand how the stuff really works. Support provided by developers and the community over mailing lists is quite amazing. > BSD may be free but as you probably > know, - the

Re: [swinog] Firewall recommendation for a rack of webservers?

2008-06-18 Thread Viktor Steinmann
I've worked with all different kinds of Firewalls - Raptor Eagle (now Symantec), ipfilter/iptables/ipchains/pf etc., Watchguard, Checkpoint, PIX/ASA among them. One thing that I have learned: The most important feature of a firewall is not it's filtering ability - every single firewall nowadays

Re: [swinog] Firewall recommendation for a rack of webservers?

2008-06-18 Thread Daniele Guazzoni
Beat Siegenthaler wrote: In this case You will be forced to deploy M$-ISA ;-) Please... He's talking about firewalls... :-) Oliver, I have pfSense in use and you can also have commercial support from them. It's stable and you can run inline-snort with autoblacklist or simple log. I guess for