Firewall Wizards mailing list archives

Re: comination of checkpoint fw-1 and raptor firewall


From: Ralf Zessin <Ralf.Zessin () maxpert de>
Date: Thu, 15 Feb 2001 00:33:15 +0100

Dieter Sarrazyn wrote:

Hi,

I have some questions concerning the combination of a checkpoint fw-1
and a raptor firewall.
1. How would you place the firewalls? First the raptor (and why) or
first the checkpoint (and why)?
2. What are the advantages of each setup?
3. Which VPN -client would you use for each setup? The securemote client
or the raptormobile client?

Many thanks for all the response!!

regards,
Dieter Sarrazyn

_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://www.nfr.com/mailman/listinfo/firewall-wizards

First,
it depends on what you want. In most Cases the raptor will be the one on
the
Internet-Front. The reason is simple - for normal case for all standard
allowed 
services there are proxies, so you have really an application level fw.

The Checkpoint has more flexibility in packet-filtering. Cause mostly
between 
raptor and checkpoint there will be specialized machines for internet
purposes
and they have to be managed from inside, the grater flexibility of a
fw-1
will be here an advantage. Also the checkpoint is great to divide
departments.


But, this depends heavily on what you or the customer wants in general.

For the VPN:    The client for the server on the front.

Regards,
        Ralf Zessin
_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://www.nfr.com/mailman/listinfo/firewall-wizards


Current thread: