PDA

View Full Version : Affordable HW Firewall


interactive
04-11-03, 11:55 PM
I know Cisco makes some great stuff, especially their PIX line of firewalls. The problem is they are expensive. I'm looking for something that will filter out DoS attacks (if possible), and such. Would need to be rackmountable, as this is for a colo enviroment. Thanks

allan
04-12-03, 12:34 AM
Look at either a PIX or a Netscreen, both have some DoS filtering capabilities, and both are very good firewalls.

jbiz718
04-12-03, 07:23 AM
Netscreen's cost are listed below

5xp - 10 user - $495
5xp - Unlimited - $995

5xt (4 port switch) - 10 user - $695
5xt (4 port switch) - Unlimited - $1195

Joe

interactive
04-12-03, 07:24 AM
Don't mean to sound stupid but what's the meaning of "users".

allan
04-12-03, 11:27 AM
Originally posted by interactive:

Don't mean to sound stupid but what's the meaning of "users".

The number of physical machines behid the firewall. Each machine counts as a "user".

jbiz718
04-12-03, 11:36 AM
Actually users in regards to netscreen has to do with VPn users. It has nothing to do with machines.

allan
04-12-03, 04:17 PM
Originally posted by jbiz718:

Actually users in regards to netscreen has to do with VPn users. It has nothing to do with machines.

Yea, Joe is right. Sorry, not enough sleep today...its that way for both the Netscreen and the PIX.

jbiz718
04-12-03, 06:53 PM
Whose Joe?

allan
04-12-03, 06:54 PM
Originally posted by jbiz718:

Whose Joe?

You, don't you remember :D.

Jay Suds
04-21-03, 03:59 PM
I would checkout sonicwall gear too. www.sonicwall.com. They have some good pricing and support much more conncurrent connections than the NetSceens. We run two of their higher end firewalls in redundant pair and they work great.

jbiz718
04-21-03, 07:05 PM
Allan

I sometimes forget.

FastServers
04-22-03, 03:52 AM
Hello:

You can not really go wrong with the Cisco PIX 501, while NetScreen and some other companies have descent firewalls we have been using the PIX 501 for quite some time for single server protection. The price can get below $500.00 if you opt for the lower end service agreement and the maximum price would be about $650 with the 24X7(replacement) service agreement in place.

jbiz718
04-22-03, 10:01 AM
I think also it depends what you are using it for.

The netscreen 5xp and 5xt have limitations on sessions and what not. I imagine the Cisco Pix's do as well.

A upgrade to a netscreen 25 or 50 starts getting steep.

racklmy.com
04-25-03, 06:44 PM
Actually users in regards to netscreen has to do with VPn users. It has nothing to do with machinesActually it has to also do with the number of IPs behind the firewall. On the 10 user version, if you put more than 10 IPs behind it it will start dropping sessions.