Best Small Biz firewall for managing outbound port policies

Posted on 2010-01-07
Last Modified: 2013-11-22
I want to replace our Microsoft ISA server with a Small Biz firewall such as Watchguard or SonicWall.

Our current policies limit outbound access to specific ports (least required) for each internal server or workstation and I want to do the same with a firewall appliance.  

I want the policy building and editing to be as simple as possilble.  Like with the ISA server, each internal host (or group of hosts) can have a single policy that lists all permitted outbound ports or protocols and then there is a Last-Default-Deny policy for all porrts for all hosts.

What small biz appliance is best for straight forward outbound port filtering managment

Question by:swb_mct
    LVL 29

    Expert Comment

    by:Michael W
    If you're willing to look at an alternative solutions, I will recommend taking a look at Untangle (, an open source network gateway considered to be a free Sonicwall alternative.

    The Policy Manager is a powerful and advanced feature of the Untangle Server. Advanced Policy Management with 'Custom Racks' is a commercial or paid option on the Untangle Server. You can, however, create 'No Rack' and 'Default Rack' policies in the Open Source version.

    Policy Manager

    Author Comment


    The only reason I want to get rid of the ISA server is to replace the server platform for a small appliance.  I have seen and recommended the UnTangle server but it is way over-kill for our office.

    I want a basic port filtering firewall for our office, equivelent to PIX but with a more intuitive management interface.  Some firwalls have simple policy management and some are messy where you have to create all sorts of objects before you can create a policy.  I am looking for "simple" port filtering management where you can see what you have and change it at a glance.
    LVL 29

    Accepted Solution

    Personally, I have a dual solution I use for my home & business needs (i.e. ESXi, virtual web & e-mail servers, workstations, etc)...

    1) Firewall/router is a Linksys RV016 unit -- equivalent to that of a Cisco ASA5505 unit. It has dual-WAN capability and can do access rules management.

    Here's a thread/example of the RV's Access Rules:

    2) In between the firewall/router and my internal network switch, I have an Untangle appliance running in "transparent bridge" mode. I have the web filter, e-mail filter, protocol control and IDS modules enabled.

    Anything that does get past the firewall, will definitely get heavily screened/checked before getting to my internal network.

    Author Comment

    The Cisco RVO16 unit looks good.  It provides the prioritized outbound access rules that I was looking for with simple policy creation and editing.  

    Author Comment

    Followup Question.   Does the RVO16 allow for multiple static addresses on the external interfaces.  The manual looks like it only supports 1 outside address per interface.   That is a deal breaker for me.
    LVL 29

    Expert Comment

    by:Michael W
    Honestly, I have never tried to set that up since I only have a single static IP for my environment.

    You might be able to use the One-To-One NAT portion for that.

    Cisco RV016 Multi WAN VPN Router

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    What Is Threat Intelligence?

    Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

    OVERVIEW This guide provides information on the process performed when the Symantec Endpoint Protection (SEP) client checks in with the Symantec Endpoint Protection Manager (SEPM). AUDIENCE Information Technology personnel responsible for suppo…
    HOW TO REMOTELY CLEAN MEROND.O WITH ESET SILENTLY PROBLEM       If you have the fortunate luck to contract the Merond.O virus on your network, it can be quite troublesome to remove as it propagates to network shares on your network. In my case, the …
    Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

    761 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    14 Experts available now in Live!

    Get 1:1 Help Now