Link to home
Start Free TrialLog in
Avatar of hcl1
hcl1

asked on

Buying a Firewall

I need help buying 2 hardware firewalls for my 2 offices. I have 4 servers running for now. Any suggestions would be awesome. Cheaper the better :)

My first office consits of the following

Database server
File Server/DC
Web Server
Time Clock Server

I am having a few people use VPN
I have a few people use Remote Desktop as well
I have a Netopia 4622 VPN router
I have a Netgear 48 Port Gigbyte Swith

------------------------------------------------------------------

My second office consits of the following
File Server/DC

Barricade Broadband Router SMC7008ABR (NO VPN)
24 port Netgear Gigabyte Switch

Thanks for the help


ASKER CERTIFIED SOLUTION
Avatar of jabiii
jabiii
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of hcl1
hcl1

ASKER

I looked at the Juniper FW but really cant find any prices for them.

Would the following work for my second office? How do these connect? Would i plug it into the switch or T1 Router? Would this even work with a T1 line?
Linksys EtherFast Cable/DSL Firewall Router with 4 Port Switch/VPN Endpoint

My first office is the more important one but i would still like to stay around $500 or less.


Thanks again
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of hcl1

ASKER

How about a FireBox SOHO 6 Firewall - 10 User License? I am confused on what the 10 User License is though. Does that mean that only 10 people could be on the network at one time? I have 25 computers on the local network and then it least 15-20 at any given time coming in to my web server. I also need 1-5 VPN connections at any given time.

Thanks
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
You can go to www.cisco.com and search for a reseller for the product. One of the famous would be www.cdw.com, give a search there as 'PIX 501'.

Make sure you are evaluating the license needs. For a couple more bucks, you can get unlimited.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of hcl1

ASKER

Well after all this information i am still undecided. Money is the big issue here. I am looking for one around $500 dollars that will do give me unlimited users and let me have it least 5 VPN users but i cant find one for that price. I guess i am asking to much. Guess i will keep looking.

Thanks
Avatar of hcl1

ASKER

Thats an awesome price but i have a couple questions on it.

1. You said above to check these out before i go with a user restriction device so i take it this has unlimited users? I can have as many people as i want coming in and out?

2. It doesnt say how many VPN licenses it comes with or if i can buy any and how much.

3. Where exactly would i place this Firewall. I have a 4622 VPN T1 router which hooks right into my 48 port Gigabit Smart Switch. Would i just plug it right into my Switch? I have never had a firewall before obviously.

4. Will this work with a T1 line.. I noticed on some firewalls they only allow so much bandwidth. I would hate to loose any of my T1 speed.

Thanks again man

SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of hcl1

ASKER

Wow... Thats pretty cheap for everything being unlimited compared to all the other routers that charge you for these licenses. Is there any catch to this Firewall? Just seems to good to be true type of thing...

Would this do anything to the netopia router being placed in a bridged mode? I would have to get a hold of earthlink because they manage the router.

Thanks for all this info it is very much appreciated.
Just tell earthink you want to handle NAT inside your organization ( you want a public ip). There is no catch, Cisco targeted the small business with the product.
Avatar of hcl1

ASKER

Oh no that sucks... I remember when i got the T1 line they didnt configure NAT on the router and they had to redo a bunch of stuff. They told me that they almost had to order a whole new line with new IP address. Would there be any way i could just use the NAT on the router instead? This might be a big hassle. Any other suggestions?
The problem with the nat remaining on the router is the amount of control you have over the line. Technically you can get the VPNs etc. to work, but the hassle would be less if you didn't have to deal with them.
The GT above.
Avatar of hcl1

ASKER

I just noticed that this was a router just like the Netopia router i have. Does an actual firewall do the same thing? Would i have to put my router in bridged mode for any firewall? I am just looking for anyway i can get around having to mess with the netopia router because earthlink can be a hassle to work with sometimes.

Thanks
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I was typing a response to a question you had not asked yet. you would have to deal with it no matter wich firewall you choose
Shawn
Avatar of hcl1

ASKER

I am going to email earthlink and ask them what all i would have to go through with taking the NAT off of the Netopia router.
Avatar of hcl1

ASKER

Ok this is what they told me...

Turning NAT off will not effect the WAN side but your LAN ip addresses will change to public ips. To turn it off just send in an email request to this email address.

I am not sure what they mean by the LAN IP address will change to public IPs. Are they talking about my Private LAN IP address? The ones everybody is using now 192.168.1.1-254.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of hcl1

ASKER

So would my LAN Ip address change? Not my Private LAN IP addresses but the ones that our like 65.50.80.159(Example)... I have about 8 of these now setup to where they point to 8 of my Private LAN IP addresses. Mainly for PcAnywhere, Remote Desktop, Secuity Camera's, Etc...

Would i turn off the VPN on the router also?

You said the outside interface of the firewall will use my public IP address. Do you mean one of the 13 Public LAN IP address that earthlink provided me? I just choose one of them to put on there?
it is a little more complicated than that. we really have to take a look at all nat statements and move foreward from there.