Link to home
Create AccountLog in
Avatar of gsr_admin
gsr_adminFlag for India

asked on

Why do I need a Firewall for my LAN ?

I am planning to implement Firewall for my LAN, I am hearing about so many in the market. How do I know which one is best for my LAN
Avatar of lamaslany
lamaslany
Flag of United Kingdom of Great Britain and Northern Ireland image

You need to draw up a list of features that you require from the firewall and then rank them in order of importance.  You can then compare this list to the various firewall solutions on the market and find the best features:money ratio for you.

Of the three firewalls you mention in your zone list I'd rate them as follows:
1.  Watchguard
2.  Cisco PIX
3.  Checkpoint

I should point out that this is a personal preference based on their suitability for the job I need them to do.  If I was to rate them for suitability in my previous job I'd have chosen:
1.  Cisco PIX
2.  Watchguard
3.  Checkpoint

Note:  I think that the Cisco PIX is end of life; I'd recommend looking at Cisco's ASA solutions


Considerations for your list (off the top of my head):
*  Inbound/Outbound Network Address Translation (NAT) and/or Port Address Translation (PAT)
*  VLAN support
*  VPN support
*  SSL VPN support
*  Reverse Proxy
*  Web/URL filtering
*  Spam Filtering
*  Deep inspection packet filtering
*  Quality of Service
*  Authentication Integration
*  High Availablility
*  Ease of support/management
*  Up front cost
*  Ongoing/maintenance cost
  • What kind of environment do you need this firewall for?
  • How many devices?
  • What kind of bandwidth do you need?
  • How many networks?
  • Is budget an issue?
  • VPN clients? linux/windows/mac?
If you have a complex environment, CheckPoint will probably serve you best, but it's also more expensive than the other alternatives.


Avatar of cv790529
cv790529

For simplicity while still being robust, your best bet is the Watchguard firewall.  A good standard is the Watchguard x550e, however, if you office is small, and you are not housing a mail server then I would proabably opt for the watchguard x20e.  Both solid choices.
ASKER CERTIFIED SOLUTION
Avatar of corematrix02
corematrix02

Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
See answer
Avatar of gsr_admin

ASKER

Thanks for the info.