Solved

IPtables vs commerical firewall

Posted on 2012-12-28
3
1,202 Views
Last Modified: 2013-01-04
Can anyone tell me the advantage of a commercial Firewall to IPtables?

I understand some of the commercial Firewalls have the ability to block at the application level (facebook, etc).  Besides this, I am clueless.  Thanks.
0
Comment
Question by:NYGiantsFan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 10

Accepted Solution

by:
Purple_Tidder earned 250 total points
ID: 38728108
Commercial firewalls typically come with tons of extra stuff that are actually useful.  Off the top of my head, uPnP is a nice one, built in VPN servers, logging, DHCP serving, DNS serving or proxying, etc etc etc.  Don't forget a lot of them come with fantastically simple WebGUIs for configuration.  Most of the higher end commercial routers come with diagnostic tools built-in as well.

IPtables is really just a basic no-frills firewall.  Of course most all the options above could be added to a linux machine running iptables but I would not trust myself to not leave huge security holes when trying to configure it all myself.  I believe this is what Untangled OS (based on Debian iirc) is focused around.

If your concern is cost, look up pfSense.  It's everything you'd probably ever want in a commercial firewall, but free and open source, based on FreeBSD.

Oh, and the big one.  Some commercial firewalls have the ability to subscribe to updates for things like AV scanning or content filtering.  I believe Sonicwall and WatchGuard products can do this.
0
 
LVL 8

Expert Comment

by:amatson78
ID: 38729302
For an opensource solution i also highly recommend iPFire. It is a very good nix based firewall and more Including proxy, content filter, etc.
0
 
LVL 12

Assisted Solution

by:DarinTCH
DarinTCH earned 250 total points
ID: 38733919
so you could learn and perfect many avenues of security- AV - IDP- Filters and then update them on a daily basis

or you but something like a Juniper SRX Firewall that does Routing and Switching and FW
and it updates the AV
and runs filters for older attacks
and can run IDP/IDS system
and simplifies the config, mgt and maint with either a 'Slow' gui
or a solid command line

and you can cluster them

can you physically achieve a similiar level - maybe - but I do not have the time or the $ to afford to stay on the VERY top of these issues - when someone else does it for me - very well and costs less in the long run

and yes some of the newest gen controls up to layer 7 and monitor the application and the traffice designated for that application...
like Palo Alto FW
0

Featured Post

MIM Survival Guide for Service Desk Managers

Major incidents can send mastered service desk processes into disorder. Systems and tools produce the data needed to resolve these incidents, but your challenge is getting that information to the right people fast. Check out the Survival Guide and begin bringing order to chaos.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Network Security Solution 7 74
What does GoogleTagMgr javascripts below do 5 86
Windows 2012 R2 Anywhere Access and PCI compliance 5 66
Barracuda WAF Training? 2 69
There is a question posted at http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2008/Q_28324159.html (http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2008/Q_28324159.html) and i…
Cybersecurity has become the buzzword of recent years and years to come. The inventions of cloud infrastructure and the Internet of Things has made us question our online safety. Let us explore how cloud- enabled cybersecurity can help us with our b…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Finding and deleting duplicate (picture) files can be a time consuming task. My wife and I, our three kids and their families all share one dilemma: Managing our pictures. Between desktops, laptops, phones, tablets, and cameras; over the last decade…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question