Asking for vendor recommendation for multi-layer firewall and link balancer

What are you guys using for firewall and link balancer to support multi ISPs.

Thanks.
tmatty102Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Sean JacksonInformation Security AnalystCommented:
Best firewalls -- Palo Alto
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
svijay_kCommented:
Cisco ASA 55xx and Barracuda Link load balancer
0
Trenton KnewOwner / Computer WhispererCommented:
Dell SonicWall NSA series can do both these jobs.  The NSA2600 is a network firewall with load balancing capabilities built in.
0
Hey MSSPs! What's your total cost of ownership?

WEBINAR: Managed security service providers often deploy & manage products from a variety of solution vendors. But is this really the best approach when it comes to saving time AND money? Join us on Aug. 15th to learn how you can improve your total cost of ownership today!

great_gentle_manCommented:
Hi,

I am using Fortinet's Fortigate 100-d with upto 22 configurable ports for multiple wan links and 60D/B with two wan ports. , with fault tolerance and load balancing.

Fortinet is market leader in its segment according gartner.

http://www.gartner.com/technology/reprints.do?id=1-1Z6XAOO&ct=140807&st=sb

But it depends upon a of lot factors, as per below in any order.
What are your link requirements.
what are your security
what is your budget,
how good is support of selected vendor in your region,
which vendor is most common in your region as it will be easier to find technical human resources.
etc.
0
Schuyler DorseyCommented:
+1
Best firewalls -- Palo Alto
0
tmatty102Author Commented:
Thanks all for your response. I'm using cisco ASA right now and would like to add an extra layer of security along with link balancer.

I have been reading a lot of good thing about Dell Sonicwall and it seems to fullfil our needs but the management seems to against them when I bring up the name. I was looking at the Link Load Balancer AscenLink by Forinet but after looking at the Fortigate 100-d, it seems to be something that we need in one unit.

@great_gentle_man, may I ask what is the size of the site that you have the Fortigate 100-d implemented? how's the performance and what are the things that you like and dislike about it?

Thanks,
0
tmatty102Author Commented:
Hi Sean Jackson and Schuyler Dorsey,

Does Palo Alto firewall feature with load balancing like the Dell SonicWall?

Thanks
0
Schuyler DorseyCommented:
It depends on what specifically you are looking to accomplish.

E.g. do you have multiple DMZ servers which host a public website and you are wanting an appliance to load balance between those two from a performance/uptime perspective

E.g. do you have a single DMZ server which hosts a public website and are wanting the public to be able to access it no matter which ISP connection they come in from

E.g. Do you want to setup all of your traffic to use one ISP and if that connection goes down, fail all traffic over to the other ISP connection.

PAN can handle 2 and 3 for sure. For option 1, I typically opt for a dedicated solution for that like the MS built in NLB or a virtual appliance.

The "next-gen" security features are also a lot more advanced, flexible, dynamic and configurable on the PANs (in my opinion).
0
great_gentle_manCommented:
about 200 users, 100 d handling every thing fine,
at the moment we are using couple of site to site vpns with multiple wan links in ft, &  nlb,
35 remote users are using ssl vpn to connect,
Internet proxy for all internal users, with logging
content filtering,
DMZ.
16gb Internal storage.
etc.etc

you can have two similar devices in high-availability mode, log analayser can also be added for logging and analysis.

If you are a windows server admin, the GUI is easy enough, although some things needs getting used to , if you are a cli person, the command prompt is very powerful, but also quite different from Cisco.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Hardware Firewalls

From novice to tech pro — start learning today.