Solved

Comparison between checkpoint VPN-Gateway and Microsoft ISA

Posted on 2002-05-28
7
2,083 Views
Last Modified: 2013-11-16
What's the comparison between checkpoint VPN-Gateway and Microsoft ISA.
Can I get documentation for the comparison of the two product?
0
Comment
Question by:Mariecel_LSI
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
7 Comments
 
LVL 23

Accepted Solution

by:
Tim Holman earned 50 total points
ID: 7042342
0
 
LVL 14

Expert Comment

by:chris_calabrese
ID: 7042370
Regardless of feature comparison, do you really want a firewall that's deeply integrated into Windows?  Regardless of how good the ISA code itself is, you can't possibly tell me this is a good idea from a security standpoint.

Not that CheckPoint has a spotless record either, but it's generally pretty solid.
0
 

Author Comment

by:Mariecel_LSI
ID: 7043493
You've given me great  nswers that will support on my documentation.You've given me what i've wanted.
0
Defend Your Organization from The Greatest Threats

Looking to fill the gaps in your security? Bring together information from the network, endpoint and threat intelligence feeds to really see what's happening in your organization. Join the WatchGuardians in their adventures fighting cyber crime!

 

Author Comment

by:Mariecel_LSI
ID: 7043510
Chris,
    Can you expound your answer pls? It's the best but I need to document this comparison of the two product.Thank you.
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 7044042
If you take the time to harden Windows properly, then it is pretty secure.
There were vulnerabilities en masse to do with IIS and IE, but if you disable these, then you're relatively safe.
However, the architecture of Windows is designed around an application based operating system.  There's a lot of junk in there that will slow it down.
Unfortunately, Microsoft never gained the trust of the security community - they always have been and always will be the #1 hack / crack target by the anarchists and anti-captialists.  Such an extensive probe of any operating system will eventually find vulnerabilities, and if it is closed, rather than open like Linux, then they are just waiting to be discovered, rather than known about and patched.
Plus with Windows you've got all the moving bits - fans, hard disks, keyboards, mice, cables, which are prone to failure and generally take systems down.
A solid state firewall (eg Cisco PIX, Netscreen) is far more reliable, and faster.  The only moving bit is a fan, and usually these are installed redundantly.
This also applies to Check Point - it is based on an I386 / hard disk architectures, although if you run it on Linux it's very fast, as it was designed around UNIX in the first place...
0
 
LVL 14

Expert Comment

by:chris_calabrese
ID: 7044819
It wasn't so much those things I was thinking about, but more that the ISA code shares a lot of the IIS and IE code for web handling (known true based on past vulnerability disclosures).  So, if IIS and IE can't be trusted, then neither can ISA.
0
 

Author Comment

by:Mariecel_LSI
ID: 7046304
Thank you Chris Calabares and Tim Holman for all teh answers.I think thats enough for my client to go on Checkpoint rather that Microsoft ISA.
0

Featured Post

Ransomware - Can it be prevented?

Worried about ransomware attacks hitting your organization?  The good news is that these attacks are predicable and therefore preventable. Learn more about how you can  stop a ransomware attacks before encryption takes place with WatchGuard Total Security!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question