• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Juniper SSG-5-SB firewall

Ciamician

n00b
Joined
Sep 22, 2013
Messages
20
Worth getting one?

They usually go for about 200-300 EUR (new) here and I managed to find a new one for about 110 EUR ($125) with shipping included. I've always wanted to mess around with a hardware-based firewall and I think this would be the right opportunity?

Any thoughts?
 
I have a SSG5 for my firewall but since I used them at work, there wasn't any learning curve. Picked it up several years ago for about $100 used. Up side is each port can be defined as a different Zone(lan). Down side is it is a 100Mb per port device. It also has decent routing ability. And can serve as a DHCP and NTP server for one or more internal zones.
 
I have a SSG5 for my firewall but since I used them at work, there wasn't any learning curve. Picked it up several years ago for about $100 used. Up side is each port can be defined as a different Zone(lan). Down side is it is a 100Mb per port device. It also has decent routing ability. And can serve as a DHCP and NTP server for one or more internal zones.

Forgive me for asking this as I'm a complete noob when it comes to firewalls....

A hardware firewall wouldn't limit the internal network speed (shares, streaming etc) right? I would just make a connection between my router and firewall, taking up one port right?

Something like this?
 
Forgive me for asking this as I'm a complete noob when it comes to firewalls....

A hardware firewall wouldn't limit the internal network speed (shares, streaming etc) right? I would just make a connection between my router and firewall, taking up one port right?

Something like this?

Yes. With the SSG5, you could connect the switch to port 0/0 and define the Zone as Trust. Your modem could connect to port 0/1 and be defined as Zone Untrust. Your Wireless could connect to port 0/2 and be defined as Zone Wireless. Any traffic between Trust devices that only go through the switch would only be limited by the switch. Traffic between Trust and Untrust(The Internet) would be limited by either the ISP speed or the SSG5, whichever was slower. Traffic between Wireless and Untrust would face the same limits. Traffic between Wireless and Trust is limited by either the speed of the WAP or the SSG5.

The advantage of splitting the Wireless and Trust sides is you can easily limit what parts of the Trust lan the wireless folks can see while allowing them full access to the outside world.

You could also hang a public server on a different port and setup a DMZ zone. Or connect a 2nd ISP.
 
Yes. With the SSG5, you could connect the switch to port 0/0 and define the Zone as Trust. Your modem could connect to port 0/1 and be defined as Zone Untrust. Your Wireless could connect to port 0/2 and be defined as Zone Wireless. Any traffic between Trust devices that only go through the switch would only be limited by the switch. Traffic between Trust and Untrust(The Internet) would be limited by either the ISP speed or the SSG5, whichever was slower. Traffic between Wireless and Untrust would face the same limits. Traffic between Wireless and Trust is limited by either the speed of the WAP or the SSG5.

The advantage of splitting the Wireless and Trust sides is you can easily limit what parts of the Trust lan the wireless folks can see while allowing them full access to the outside world.

You could also hang a public server on a different port and setup a DMZ zone. Or connect a 2nd ISP.

Great.

Thanks for the reply :)
 
Back
Top