Solved

Firewall recommendation

Posted on 2013-01-08
8
371 Views
Last Modified: 2013-01-14
Hello,

We are looking for a all-in-one firewall box with the following functions. Anyone have any recommendations:

- Good standard >100 mbit WAN firewall throughput
- SSL VPN portal style built in, support for mac and pc. a so called clientless solution, user logs in with AD account and should either be able to start a RDP session or a vpn tunnel
- support for pc and mac required for the above vpn function
- If possible the firewall should support two separate LANs on the inside, and support bandwithcontrol for each LAN (split the internet speed between two supported LANs behind the firewall with different ip subnets).

Any recommendations amongst the well known brands?

thanks,
joe
0
Comment
Question by:joebilek
  • 4
  • 2
  • 2
8 Comments
 
LVL 25

Expert Comment

by:Tony Giangreco
ID: 38757040
Try the Cisco small business Firewall SA520. We use them and they work very well. Cisco support has been excellent on it.
0
 
LVL 1

Author Comment

by:joebilek
ID: 38757048
Thanks. Do you know if it supports both the vpn and bandwith control scenarios?
0
 
LVL 1

Author Comment

by:joebilek
ID: 38757053
should mention we need the SSL VPN tunnels to be at approx 5 concurrent from start, with option to grow.
0
 
LVL 25

Expert Comment

by:Tony Giangreco
ID: 38757063
0
Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

 
LVL 1

Author Comment

by:joebilek
ID: 38757121
Thanks, it does not however seem to support LAN port bandwidth control for what I can see.
0
 
LVL 25

Accepted Solution

by:
RobMobility earned 500 total points
ID: 38757317
Hi,

I believe that a Cisco ASA 5512-X would fit the bill.

It has 6 Gigabit interfaces, 500Mbps real-world firewall throughput, SSL as well as DTLS, IPSEC, L2TP VPNs, supports VPN portals and has QOS for bandwidth control.

AnyConnect Windows and MAC clients available for VPN termination using IPSEC (250 peers out of the box) - use AnyConnect Essentials.

AnyConnect Premium licences are required to unlock full SSL features including portal etc. Available in ranges of licences (has 2 concurrent SSL bundled) for upgrading to 10, 25, 50 etc.

More information here:

http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html

Regards,


RobMobility.
0
 
LVL 1

Author Comment

by:joebilek
ID: 38764530
Thanks! Is there any cheaper model that has anyconnect premium and QoS such as this one?

ASA 5505 series does not?

Joe
0
 
LVL 25

Expert Comment

by:RobMobility
ID: 38774989
Hi,

I don't think the 5505 does but a 5510 might:

http://www.ebay.co.uk/itm/NEW-SEALED-Cisco-ASA5510-SSL50-K9-ASA-5510-SSL-IPsec-VPN-Adaptive-Security-App-/120993649941?pt=US_Firewall_VPN_Devices&hash=item1c2bc89515

That includes 100 SSL licences - best to contact the vendor to make sure that one does everything you need it to.

Regards,


RobMobility.
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
IKEv2 VS  SSTP 4 77
TCP Connection Established 14 71
VPN Shared folder Access 3 58
Sync Azure AD to a local AD Server 4 34
When you connect to your workplace's VPN, you may not notice that you are using your workplace's servers to serve up webpages.  This might be undesirable since the workplace can log all the places you've been.  It also might be very slow to load pag…
I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now