?
Solved

tips for new firewall/router with vpn capabilities

Posted on 2008-06-26
4
Medium Priority
?
306 Views
Last Modified: 2008-06-30
in my org we have an old netscreen 5xp. with our growing staff we are running into a user limit on this firewall recently, after contacting juniper i found out this router is end of life and can only support ten users. so i think its time for a new one. i would like to stick wiht netscreens because it has been good in the past and i should be able to up my config. the sales guy at juniper suggested a ssg5, which has no user limit and i can buy vpn clients for $110 for 10 clients. just wanted some input on any pros or cons of this or any other similar device. some preliminary quotes i got are about
700 for the router
70 for one year next day support
110 for 10 clients

thanks,
cory
0
Comment
Question by:cfischer225
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 1

Assisted Solution

by:itmonitor
itmonitor earned 249 total points
ID: 21878572
I use watchguard firewalls and they have a very easy vpn manager.  Depending on the model you will receive different features.  
0
 

Author Comment

by:cfischer225
ID: 21878782
do watchguards have routers builtin or just firewalls?
0
 
LVL 23

Assisted Solution

by:TheCleaner
TheCleaner earned 249 total points
ID: 21880800
I have an SSG5 at home...it's decent.  SSG20 is the next line up and is fantastic for a small office.

Not sure why you'd need to buy VPN clients unless you don't want to use Windows 2003 server's built in RRAS for VPN.

Your config should transfer over somewhat ok as long as you are close to the same ScreenOS version.  I'd make note of everything ahead of time though just in case.

(For the record, I run SSG5's, SSG20's, and SSG520's and they all perform great)
0
 
LVL 32

Accepted Solution

by:
dpk_wal earned 252 total points
ID: 21880888
5xp last SOS supported was 5.0 and SSG support a minimum 5.4; however, you can do get config from the 5xp and load it to the new SSG series.

I always recommend to upgrade to the same vendor (if possible) for the simple reason of product familiarity. If there is a good product but you are not too sure on configuring it, then it is of no use.

Few of the things which Watchguard(WG) smaller X Edge boxes have which Juniper SSG don't are:
WG X Edge has capability to act as PPTP server so can accept incoming PPTP connection from windows clients (so no need to install any additional licenses), includes SSL VPN license (only 1 though) as well.
However, Juniper scores over in terms of maximum throughput both firewall and VPN.

I would say do a price/feature comparison between different vendors and then zero in on a single product/model.

Please looks at vendors (not in any order):
Juniper SSG series, WG X Edge series, Cisco ASA series, Sonicwall

Please let know if you need clarification about some specific feature/box capability.

Thank you.
0

Featured Post

Four New Appliances. Same Industry-leading Speeds.

But don't take it from us.  The Firebox M370 is Miercom tested and Miercom approved, outperforming its competitors for stateless and stateful traffic throughput scenarios.  Learn more about the M370, M470, M570 and M670 and find the right solution for your organization today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month10 days, 14 hours left to enroll

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question