Educause Security Discussion mailing list archives

Re: Firewalls


From: Alan Nord <anord () MACALESTER EDU>
Date: Wed, 17 Jul 2013 11:20:40 -0500

We just replaced a pair of Cisco ASA 5550s with Palo Alto 3020s.  Could not
be happier with the feature set and the visibility Palo Alto provides.  If
you can, do a 30 day demo of each product and you will see the difference.
 We are using nearly every feature the box provides and have not had any
performance issues.  Tough part is the mind set of applications vs. ports,
but once you get that down you are set.  I am ready for the semester to
start to put this thing to the test.


On Fri, Jun 28, 2013 at 1:23 PM, John Kaftan <jkaftan () utica edu> wrote:

We have been using Fortinet 1000as for the last 6 years.  We are currently
in a firewall RFP to replace these boxes and wonder if anyone out there can
help.

We are planning on having two firewalls in an HA configuration.  We have
about 1500 users on campus and about 2500 distance and commuter students.
 We have a 1 Gb internet connection.  We are only looking to protect our
edge.

We are looking at the following options.


Fortigate 1000cs
Cisco ASA 5580s
Palo-Alto 5020s

Reading through the literature can be overwhelming with UTM firewalls.
 I'd just like to know if anybody is using one of these platforms and the
pros and cons you see.  Specifically, we are concerned about support and
how the boxes perform as you turn on features, also usability.

Thanks

--
John Kaftan
IT Infrastructure Manager
Utica College




-- 
Alan Nord, CCNA
Infrastructure Manager
Information Technology Services
Macalester College
1600 Grand Avenue
St. Paul, MN 55105

Current thread: