?
Solved

Firewall Recommendation

Posted on 2006-10-24
6
Medium Priority
?
238 Views
Last Modified: 2013-11-16
Hi,

I work for a school that has roughly 1200 students and say 500 computers. We are having bandwidth issues and are about to purchase a net equalizer to help with this. However it will not do everything we need, we are wanting a firewall to use to do some basic things and price is a huge concern. Where I used to work we used a sonicwall and could view the most popular sites visited. This would allow us to have the kids tell us what the cool amazing new sites were and then we could block them. I am looking for an appliance that allows this at a cheaper cost.

Basically I want to be able to see the most visited sites/ip's and be able to block sites easily. I need an easy to use device that we will not have to mess with too much.


Thanks,
Chad
0
Comment
Question by:ItsChad
6 Comments
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 17800788
Just about any firewall will do, Linux IPTables is a great firewall, and Linux supports "traffic shaping" which allows you to limit each machines connection throughput or a group of machines, an IP range etc... http://en.wikipedia.org/wiki/Traffic_shaping (QOS being enabled on the NIC of each PC is a must) The external links are great
Most enterprise routers can do traffic shaping, Cisco, Juniper, netgear etc...
Ntop can create the graphs and stats you desire, there is a Unix/Linux version and a win32 ported version
*nix: http://www.ntop.org/overview.html
win32: http://www.openxtra.co.uk/freestuff/ntop-xtra.php

I think ntop will provide you with more than you need, it doesn't write much to disk, so make sure you have lots o ram. Cisco pix's are great firewalls also, the 506e would likely suit your needs no problem. http://www.newegg.com/Product/Product.asp?Item=N82E16833120315
-rich
0
 

Author Comment

by:ItsChad
ID: 17800810
We have a pix501 however it says it has a 10 user license.....
0
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 2000 total points
ID: 17800845
Do all 500 pc's connect through the firewall currently? Is there some sort of NAT/PAT before the firewall allowing more than 10 ip's at a time?
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_data_sheet09186a0080091b18.html
10-User License
The Cisco PIX 501 10-user license supports up to 10 concurrent source IP addresses from your internal network to traverse through the Cisco PIX 501. The integrated DHCP server supports up to 32 DHCP leases. As your needs grow, both 50 user and unlimited user upgrade licenses are available, allowing you to extend your investment in Cisco PIX 501 equipment.
The 506e has: Concurrent connections: 25,000
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_data_sheet09186a0080091b13.html
-rich
0
When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot has fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

 
LVL 38

Expert Comment

by:Rich Rumble
ID: 17800859
http://www.pricegrabber.com/search_getprod.php/masterid=923020/
7,500 max connections with the 501 "unlimited" license
-rich
0
 
LVL 4

Expert Comment

by:LBACIS
ID: 17807768
A Watchguard X700 will do exactly what you need.
0
 

Expert Comment

by:naveen_b81
ID: 17809824
if you have worked on linus, you can use Dansgaurdian with squid proxy server to restrict internet access. It is absolutely free of cost...
0

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes Administrators rights are not enough. These cases call for the SYSTEM account. The process in this article outlines the steps required to execute commands using the SYSTEM account.
Let's take a look into the basics of ransomware—how it spreads, how it can hurt us, and why a disaster recovery plan is important.
This video Micro Tutorial shows how to password-protect PDF files with free software. Many software products can do this, such as Adobe Acrobat (but not Adobe Reader), Nuance PaperPort, and Nuance Power PDF, but they are not free products. This vide…
Is your data getting by on basic protection measures? In today’s climate of debilitating malware and ransomware—like WannaCry—that may not be enough. You need to establish more than basics, like a recovery plan that protects both data and endpoints.…
Suggested Courses

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question