We help IT Professionals succeed at work.

Firewall Recommendation

ItsChad
ItsChad asked
on
Medium Priority
251 Views
Last Modified: 2013-11-16
Hi,

I work for a school that has roughly 1200 students and say 500 computers. We are having bandwidth issues and are about to purchase a net equalizer to help with this. However it will not do everything we need, we are wanting a firewall to use to do some basic things and price is a huge concern. Where I used to work we used a sonicwall and could view the most popular sites visited. This would allow us to have the kids tell us what the cool amazing new sites were and then we could block them. I am looking for an appliance that allows this at a cheaper cost.

Basically I want to be able to see the most visited sites/ip's and be able to block sites easily. I need an easy to use device that we will not have to mess with too much.


Thanks,
Chad
Comment
Watch Question

Rich RumbleSecurity Samurai
CERTIFIED EXPERT
Top Expert 2006

Commented:
Just about any firewall will do, Linux IPTables is a great firewall, and Linux supports "traffic shaping" which allows you to limit each machines connection throughput or a group of machines, an IP range etc... http://en.wikipedia.org/wiki/Traffic_shaping (QOS being enabled on the NIC of each PC is a must) The external links are great
Most enterprise routers can do traffic shaping, Cisco, Juniper, netgear etc...
Ntop can create the graphs and stats you desire, there is a Unix/Linux version and a win32 ported version
*nix: http://www.ntop.org/overview.html
win32: http://www.openxtra.co.uk/freestuff/ntop-xtra.php

I think ntop will provide you with more than you need, it doesn't write much to disk, so make sure you have lots o ram. Cisco pix's are great firewalls also, the 506e would likely suit your needs no problem. http://www.newegg.com/Product/Product.asp?Item=N82E16833120315
-rich

Author

Commented:
We have a pix501 however it says it has a 10 user license.....
Security Samurai
CERTIFIED EXPERT
Top Expert 2006
Commented:
Do all 500 pc's connect through the firewall currently? Is there some sort of NAT/PAT before the firewall allowing more than 10 ip's at a time?
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_data_sheet09186a0080091b18.html
10-User License
The Cisco PIX 501 10-user license supports up to 10 concurrent source IP addresses from your internal network to traverse through the Cisco PIX 501. The integrated DHCP server supports up to 32 DHCP leases. As your needs grow, both 50 user and unlimited user upgrade licenses are available, allowing you to extend your investment in Cisco PIX 501 equipment.
The 506e has: Concurrent connections: 25,000
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_data_sheet09186a0080091b13.html
-rich

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts
Rich RumbleSecurity Samurai
CERTIFIED EXPERT
Top Expert 2006

Commented:
http://www.pricegrabber.com/search_getprod.php/masterid=923020/
7,500 max connections with the 501 "unlimited" license
-rich

Commented:
A Watchguard X700 will do exactly what you need.
if you have worked on linus, you can use Dansgaurdian with squid proxy server to restrict internet access. It is absolutely free of cost...
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.