|
A software firewall will generally be more vulnerable than a hardware box - but if you set it up properly then i don't see why it should pose a problem. I doubt it takes its toll on performance either. I know I am happy enough to use my own firewall rules with iptables to keep me safe for a solitary server.
However, at least with a hardware box you can protect multiple servers, there is less on the hardware end to mess with and it is simpler to manage. As for performance I'm sure both solutions can handle whatever connection you throw at it for simple web traffic.
|