Solved

IPtables vs commerical firewall

Posted on 2012-12-28
3
1,161 Views
Last Modified: 2013-01-04
Can anyone tell me the advantage of a commercial Firewall to IPtables?

I understand some of the commercial Firewalls have the ability to block at the application level (facebook, etc).  Besides this, I am clueless.  Thanks.
0
Comment
Question by:NYGiantsFan
3 Comments
 
LVL 10

Accepted Solution

by:
Purple_Tidder earned 250 total points
ID: 38728108
Commercial firewalls typically come with tons of extra stuff that are actually useful.  Off the top of my head, uPnP is a nice one, built in VPN servers, logging, DHCP serving, DNS serving or proxying, etc etc etc.  Don't forget a lot of them come with fantastically simple WebGUIs for configuration.  Most of the higher end commercial routers come with diagnostic tools built-in as well.

IPtables is really just a basic no-frills firewall.  Of course most all the options above could be added to a linux machine running iptables but I would not trust myself to not leave huge security holes when trying to configure it all myself.  I believe this is what Untangled OS (based on Debian iirc) is focused around.

If your concern is cost, look up pfSense.  It's everything you'd probably ever want in a commercial firewall, but free and open source, based on FreeBSD.

Oh, and the big one.  Some commercial firewalls have the ability to subscribe to updates for things like AV scanning or content filtering.  I believe Sonicwall and WatchGuard products can do this.
0
 
LVL 8

Expert Comment

by:amatson78
ID: 38729302
For an opensource solution i also highly recommend iPFire. It is a very good nix based firewall and more Including proxy, content filter, etc.
0
 
LVL 12

Assisted Solution

by:DarinTCH
DarinTCH earned 250 total points
ID: 38733919
so you could learn and perfect many avenues of security- AV - IDP- Filters and then update them on a daily basis

or you but something like a Juniper SRX Firewall that does Routing and Switching and FW
and it updates the AV
and runs filters for older attacks
and can run IDP/IDS system
and simplifies the config, mgt and maint with either a 'Slow' gui
or a solid command line

and you can cluster them

can you physically achieve a similiar level - maybe - but I do not have the time or the $ to afford to stay on the VERY top of these issues - when someone else does it for me - very well and costs less in the long run

and yes some of the newest gen controls up to layer 7 and monitor the application and the traffice designated for that application...
like Palo Alto FW
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Phishing is at the top of most security top 10 efforts you should be pursuing in 2016 and beyond. If you don't have phishing incorporated into your Security Awareness Program yet, now is the time. Phishers, and the scams they use, are only going to …
Transferring data across the virtual world became simpler but protecting it is becoming a real security challenge.  How to approach cyber security  in today's business world!
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question