Link to home
Start Free TrialLog in
Avatar of ItsChad
ItsChad

asked on

Firewall Recommendation

Hi,

I work for a school that has roughly 1200 students and say 500 computers. We are having bandwidth issues and are about to purchase a net equalizer to help with this. However it will not do everything we need, we are wanting a firewall to use to do some basic things and price is a huge concern. Where I used to work we used a sonicwall and could view the most popular sites visited. This would allow us to have the kids tell us what the cool amazing new sites were and then we could block them. I am looking for an appliance that allows this at a cheaper cost.

Basically I want to be able to see the most visited sites/ip's and be able to block sites easily. I need an easy to use device that we will not have to mess with too much.


Thanks,
Chad
Avatar of Rich Rumble
Rich Rumble
Flag of United States of America image

Just about any firewall will do, Linux IPTables is a great firewall, and Linux supports "traffic shaping" which allows you to limit each machines connection throughput or a group of machines, an IP range etc... http://en.wikipedia.org/wiki/Traffic_shaping (QOS being enabled on the NIC of each PC is a must) The external links are great
Most enterprise routers can do traffic shaping, Cisco, Juniper, netgear etc...
Ntop can create the graphs and stats you desire, there is a Unix/Linux version and a win32 ported version
*nix: http://www.ntop.org/overview.html
win32: http://www.openxtra.co.uk/freestuff/ntop-xtra.php

I think ntop will provide you with more than you need, it doesn't write much to disk, so make sure you have lots o ram. Cisco pix's are great firewalls also, the 506e would likely suit your needs no problem. http://www.newegg.com/Product/Product.asp?Item=N82E16833120315
-rich
Avatar of ItsChad
ItsChad

ASKER

We have a pix501 however it says it has a 10 user license.....
ASKER CERTIFIED SOLUTION
Avatar of Rich Rumble
Rich Rumble
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
http://www.pricegrabber.com/search_getprod.php/masterid=923020/
7,500 max connections with the 501 "unlimited" license
-rich
A Watchguard X700 will do exactly what you need.
if you have worked on linus, you can use Dansgaurdian with squid proxy server to restrict internet access. It is absolutely free of cost...