Link to home
Start Free TrialLog in
Avatar of naj2576
naj2576

asked on

Need a VPN capable Firewall/Router

Okay, here goes (first time posting a question)

I need to purchase a Firewall/Router that will allow multiple concurrent VPN connections from different locations.  I have employees that travel and need access to the Office LAN.  As of now I have a Netgear FVS318 ProSafe Firewall/Router, but it only supports 8 IPSEC connections.  I want to put the new Firewall/Router "behind" the FVS318 (supports 100 IPSEC connections) to create a sort of DMZ and forward all VPN connections to the new Firewall/Router.

My questions are:

 - What are some recommendations for the new Firewall/Router that I need?  I have looked into Netgear FVL328, and my boss loves it because it is cheap, but I'm not sure how well it will perform or how easy it is to setup/use.  I've also looked briefly at a CISCO PIX 501, but the price tag is a little high and I've heard that CISCO products are tough to configure and use.

- As far as VPN protocols, I hear that IPSEC is very secure but difficult to setup and use, while PPTP is less secure but easier to use.  Any advice on which protocol to use would be helpful.  Do the security benefits of IPSEC over PPTP out weigh the ease of use benefits of PPTP?

- What else should I look for in a new Firewall/Router?  My company is not very big, but we are growing rapidly.  Do some solutions scale better than others.

Thanks In advance.
ASKER CERTIFIED SOLUTION
Avatar of Les Moore
Les Moore
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I would also recommend upgrading your existing box - it will be a lot easier to support in the long run.
Is there a bigger Netgear box you can upgrade to ?
Avatar of naj2576
naj2576

ASKER

Irmoore,

Thank you for all the helpful advice.  I've convinced my boss to up my budget a little so that I can get a firewall with a little more horsepower behind it, but I still have to keep things under $1K.

I was almost ready to go with the PIX 506e after looking at it, but now another person I've talked to is pushing SonicWall's TZ170 or PRO 2040.  He believes they are far easier to maintain(for someone not familiar with Cisco IOS) and are more scalable than the PIX.  

Any thoughts on these firewalls or SonicWall in general?
According to SonicWall's own product chart, the TZ170 is targeted for 10 VPN connections, the 2040 at 50. In that case, I'd have to recommend the 2040.
http://www.sonicwall.com/products/vpnapp.html

However, I've tried several times to find documentation on Sonicwall's web site and it is very difficult to find anything other than the quick setup guides. Get into the documentation for the actual SonicOS, and I've found it quite overwhelming...
I'll take the PIX any day...

You'll have to make your own decision based on your own comfort level and skill sets..