Security Basics mailing list archives

RE: Firewall recommendations?


From: "Ernest Lau" <bugtraq () elau net>
Date: Wed, 12 Mar 2003 17:16:13 -0800

Check out Fortigate also...  www.fortinet.com  It is started by the same
founder @ Netscreen.  

As the only systems in the world that are triple-certified by the ICSA
(for antivirus, IPSec, and firewall functionality), FortiGate systems
deliver the highest level of security available.



-----Original Message-----
From: Bhavin [mailto:bhavin () securematics com] 
Sent: Tuesday, March 11, 2003 4:08 PM
To: sflist-secbasic () reliance net; security-basics () securityfocus com
Subject: RE: Firewall recommendations?


I have no comments on the technical support of NetScreen but there is
one more thing to be considered. As  a tech support engineer for both
the products (SonicWALL as well NetScreen), NetScreen has more features
compared to SonicWALL. You ask it and NetScreen has it. 
Thanks,
Bhavin.


-----Original Message-----
From: John Tolmachoff [mailto:sflist-secbasic () reliance net] 
Sent: Monday, March 10, 2003 10:48 AM
To: security-basics () securityfocus com
Subject: RE: Firewall recommendations?

While I see people recommend NetScreen, I can not based on my experience
with their techs, which includes level 2 techs.

While researching options for a firewall for a client, none of the techs
at NetScreen that I talked to could answer a basic question: Does
NetScreen firewall do stateful packet inspection? 5 different techs,
including a senior lead tech, could not answer yes or no. (The fact that
it does is not the point here, the knowledge by their techs is.)

We have 9 Sonicwalls installed and am very happy with them. (Clients and
in-house.)

The comment about ISA server in a environment where security is at most,
I would recommend a primary firewall, such as a Sonicwall, as the first
line of defense, (with a DMZ behind that in Normal Mode,) then ISA
server between the DMZ and the Internal LAN.

ISA is an excellent product for integrating with a LAN. However, as
someone else said, when it comes to security, there is on one end-all
product.

John Tolmachoff MCSE, CSSA
IT Manager, Network Engineer
RelianceSoft, Inc.
Fullerton, CA  92835
www.reliancesoft.com








Current thread: