Solved

tips for new firewall/router with vpn capabilities

Posted on 2008-06-26
4
300 Views
Last Modified: 2008-06-30
in my org we have an old netscreen 5xp. with our growing staff we are running into a user limit on this firewall recently, after contacting juniper i found out this router is end of life and can only support ten users. so i think its time for a new one. i would like to stick wiht netscreens because it has been good in the past and i should be able to up my config. the sales guy at juniper suggested a ssg5, which has no user limit and i can buy vpn clients for $110 for 10 clients. just wanted some input on any pros or cons of this or any other similar device. some preliminary quotes i got are about
700 for the router
70 for one year next day support
110 for 10 clients

thanks,
cory
0
Comment
Question by:cfischer225
4 Comments
 
LVL 1

Assisted Solution

by:itmonitor
itmonitor earned 83 total points
ID: 21878572
I use watchguard firewalls and they have a very easy vpn manager.  Depending on the model you will receive different features.  
0
 

Author Comment

by:cfischer225
ID: 21878782
do watchguards have routers builtin or just firewalls?
0
 
LVL 23

Assisted Solution

by:TheCleaner
TheCleaner earned 83 total points
ID: 21880800
I have an SSG5 at home...it's decent.  SSG20 is the next line up and is fantastic for a small office.

Not sure why you'd need to buy VPN clients unless you don't want to use Windows 2003 server's built in RRAS for VPN.

Your config should transfer over somewhat ok as long as you are close to the same ScreenOS version.  I'd make note of everything ahead of time though just in case.

(For the record, I run SSG5's, SSG20's, and SSG520's and they all perform great)
0
 
LVL 32

Accepted Solution

by:
dpk_wal earned 84 total points
ID: 21880888
5xp last SOS supported was 5.0 and SSG support a minimum 5.4; however, you can do get config from the 5xp and load it to the new SSG series.

I always recommend to upgrade to the same vendor (if possible) for the simple reason of product familiarity. If there is a good product but you are not too sure on configuring it, then it is of no use.

Few of the things which Watchguard(WG) smaller X Edge boxes have which Juniper SSG don't are:
WG X Edge has capability to act as PPTP server so can accept incoming PPTP connection from windows clients (so no need to install any additional licenses), includes SSL VPN license (only 1 though) as well.
However, Juniper scores over in terms of maximum throughput both firewall and VPN.

I would say do a price/feature comparison between different vendors and then zero in on a single product/model.

Please looks at vendors (not in any order):
Juniper SSG series, WG X Edge series, Cisco ASA series, Sonicwall

Please let know if you need clarification about some specific feature/box capability.

Thank you.
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
EIGRP Full Mesh 2 62
Add Mac address reservation to Sonicwall TZ 210 router 1 44
DHCP Server 14 62
Dedicated I.P., VPN, both, neither, or what? 12 25
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now