24th November 2007
|
#1 (permalink)
|
 Certified Host
Join Date: Nov 2005
Location: EC1
Age: 27
Posts: 1,014
|
Firewalls
As everyone know... I love everything Juniper. To that tune, we are looking for a set of new firewalls and are thinking of these in routed mode (OSPF stub, iBGP defaults) as A/A pairs:
http://www.juniper.net/products_and_...ies/index.html
Anyone have any previous experience with them? I am hoping to get one on eval for a play.
__________________
Goscomb Technologies Limited - www.goscomb.net / AS39326
E: sales@goscomb.net P: +44 (0) 203 129 4400 F: +44 (0) 203 129 4410
Free IPv4/IPv6 Dialup! p: 08456043047 u: dial@goscomb.net.uk p: dial
IP Transit :: Colocation :: Dedicated Servers :: Leased Lines :: DSL
Registered in England and Wales No. 05672987 - VAT Registration No. 853 7954 80
|
|
|
24th November 2007
|
#2 (permalink)
|
 VIP Host
Join Date: Nov 2001
Location: Derbyshire
Posts: 6,471
|
I've not heard fantastic things about Netscreen for some time now, we were looking at them + the Juniper IPS product for a customer, in the end we went with TopLayer.
|
|
|
24th November 2007
|
#3 (permalink)
|
 Basic Host
Join Date: Sep 2005
Age: 38
Posts: 51
|
We have used many Juniper products, and we personally prefer the TopLayer applications, as these are proving much more effective.
|
|
|
25th November 2007
|
#4 (permalink)
|
 VIP Host
Join Date: Aug 2002
Location: London, England
Posts: 3,376
|
Have a look at this thread
__________________
••• Mark Castle ••• Secura Hosting Ltd •••
••• Managed Hosting •••
••• AS29452 • UK Company Reg No: 04330657 • VAT Number: 789 2703 81 • Sales: 0845 123 2632 •••
My views are my own and not those of my company.
|
|
|
25th November 2007
|
#5 (permalink)
|
 VIP Host
Join Date: Jul 2003
Location: London, E1
Age: 38
Posts: 3,141
|
__________________
Ricky
Business Development Manager - Serverstream Ltd
Managed Services | Dedicated Servers | Network Security
T: +44 (0)20 7517 0606 E: ricky@serverstream.net
Note: All of the views above are my own and not in any way representative of my company.
|
|
|
25th November 2007
|
#6 (permalink)
|
 Certified Host
Join Date: Nov 2005
Location: EC1
Age: 27
Posts: 1,014
|
PIX doesn't do all we need
Karl: this is the SSG i'm looking at, not netscreen. same screenos yes, but iirc the boxes are a lot more powerful, no?
Does anyone have any toplayer pricing info and a spec sheet?
__________________
Goscomb Technologies Limited - www.goscomb.net / AS39326
E: sales@goscomb.net P: +44 (0) 203 129 4400 F: +44 (0) 203 129 4410
Free IPv4/IPv6 Dialup! p: 08456043047 u: dial@goscomb.net.uk p: dial
IP Transit :: Colocation :: Dedicated Servers :: Leased Lines :: DSL
Registered in England and Wales No. 05672987 - VAT Registration No. 853 7954 80
|
|
|
25th November 2007
|
#7 (permalink)
|
 VIP Host
Join Date: Nov 2001
Location: Derbyshire
Posts: 6,471
|
At the end of the day, the SSG is a Celeron or a P4 running stuff in software - It's the same as the J-Series routers
Pricing for TopLayer - from £10k from memory.
|
|
|
25th November 2007
|
#8 (permalink)
|
 VIP Host
Join Date: Aug 2005
Posts: 4,192
|
Cisco ASA for the Lower budget clients, Checkpoint for the higher bidget clients.
Sorted.
|
|
|
26th November 2007
|
#9 (permalink)
|
Join Date: Jan 2005
Posts: 139
|
Goscomb - Interested to hear what the PIX's or ASA's dont do that you need? Always good to keep abreast of customer firewall/solution demands.
__________________
Matthew Parks
[Any views expressed on this forum are my own, and do not represent the views of any companies I may be associated with]
|
|
|
26th November 2007
|
#10 (permalink)
|
 Certified Host
Join Date: Nov 2005
Location: EC1
Age: 27
Posts: 1,014
|
Quote:
Originally Posted by MattParks
Goscomb - Interested to hear what the PIX's or ASA's dont do that you need? Always good to keep abreast of customer firewall/solution demands.
|
Unless they do routed mode these days and support OSPF + BGP and IPv6 ? They didn't used to the last time i looked...
__________________
Goscomb Technologies Limited - www.goscomb.net / AS39326
E: sales@goscomb.net P: +44 (0) 203 129 4400 F: +44 (0) 203 129 4410
Free IPv4/IPv6 Dialup! p: 08456043047 u: dial@goscomb.net.uk p: dial
IP Transit :: Colocation :: Dedicated Servers :: Leased Lines :: DSL
Registered in England and Wales No. 05672987 - VAT Registration No. 853 7954 80
|
|
|
26th November 2007
|
#11 (permalink)
|
 VIP Host
Join Date: Jun 2003
Posts: 1,891
|
I went for the Cisco's because they seem to be pretty much standard in my price range and I've rarely heard a bad word said about them. (except from nokia checkpoint nerds)
I was put off by the Netscreens by a couple of members on here and also a friend who almost broke into a sweat during a 15 minute rant damning them to hell!
They will do routed mode and OSPF and IPV6 but I'm not sure about BGP.
__________________
Mooharr
E-Mail Hosting Services
These are not my views and i cannot be held accountable for anything he says.
|
|
|
27th November 2007
|
#12 (permalink)
|
 VIP Host
Join Date: Sep 2005
Location: Leeds
Posts: 1,638
|
Quote:
Originally Posted by goscombtech
Unless they do routed mode these days and support OSPF + BGP and IPv6 ? They didn't used to the last time i looked...
|
They do (and as far as I recall always have) supported routing, both Pix's and ASAs.
They certainly do OSPF and BGP, not sure about ipv6 tho tbh. Got two ASAs to install tomorrow, so will take a look, but other than that ticks the boxes, and ASAs (so long as you don't want Anti V/Spam, Phishing etc etc) stuff on them are comparatively cheap as chips. £1300 ish for a 350mb/s firewall only unit, 6k connections per sec, 130k tops connections. Ok, that is the baby of the rack mounts (5510 in the Plus version - more max connections and vlans) but still V sensibly priced IMO if you want some gig ports and gig plus capability.
Quick compares > http://www.cisco.com/en/US/products/...omparison.html
|
|
|
28th November 2007
|
#13 (permalink)
|
 VIP Host
Join Date: Nov 2001
Location: Derbyshire
Posts: 6,471
|
From memory, a recent NANOG thread said that whilst they do support IPv6, it's a very limited feature set compared to the IPv4 support.
|
|
|
29th November 2007
|
#14 (permalink)
|
 Certified Host
Join Date: May 2003
Posts: 418
|
We have about 70 Juniper Netscreen/SSG firewalls in operation ranging from the 5GT to SSG520. We did have issues with the 5GT however Juniper support were quick to resolve this and all seems to be humming along fine.
Some units are almost 4 years old but still work perfectly.
Speak to the guys at http://www.1stsecuritywarehouse.com
|
|
|
22nd January 2008
|
#15 (permalink)
|
 VIP Host
Join Date: Aug 2007
Location: Lincoln, UK
Posts: 1,670
|
Not used any Juniper kit, but I swear by Fortinet's FortiGates. Hardware accelerated with AntiVirus and IPS/IDS. You can pick up a FortiGate 400A for about £4500 which will do 450Mbps across a pair of gigabit and four 10/100 ports if memory serves me correctly. Awesome performance and no bloody host count licensing (I'm looking at you Check Point). They do OSPF and BGP as well.
I think Check Point still wins out with management and logging tools though, they just have a much more mature tool set.
Not had the joy of playing with Crossbeams or anything like that, but I've worked with a lot of Nokias running everything from 4.1 to NG R55 and they are all right, not fantastic, but all right. They don't seem to work well with more than 50-60 VLANs and getting them to crash and reboot isn't too hard if you know what you are doing but if you just leave them alone then they are fine. Have worked with some in a data centre environment that have been up for years, running hundreds of VPNs and the only problems are when the hardware eventually dies.
Nokias do OSPF and BGP, as do other Check Point appliances like the Corssbeams but with Check Point it is up to the appliance/OS to provide routing protocol support, something that dedicated, integrated systems don't suffer from.
Last edited by freethought; 22nd January 2008 at 12:39 AM.
|
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is On
|
|
|
Similar Threads
|
| Thread |
Thread Starter |
Forum |
Replies |
Last Post |
|
Software Firewalls
|
richard |
General Chit Chat & Discussion |
11 |
22nd July 2002 02:17 PM |
| Networking, Routing and Transit Routers, Switches, Layer 2, Layer 3, BGP or Wireless - Chat about it here |
|
|
Powered by vBulletin® Version 3.8.0 Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
|