Small Business Firewall

If you end up on the fence between Sonicwall and FortiGate, I strongly urge towards FortiGate as Sonicwall's licensing is pretty aweful.

FortiGate support is top notch compared to Sonicwall. FortiGate support is Canadian, Sonicwall is Indian.
 
mmmmmmmmmm Zyxel Zywall 110...

subscribed

Could those of you with the 110 tell me how a pfSense box such as a Netgate m1n1wall 2D3 / 2D13 compares? (Not looking at price.)



That device is a cute upgrade from DD-WRT, but these days it's kind of laughable with the specs and selling price. Not to mention it kind of embarrasses PFsense. It's closer in competition with the USG 20(w) or USG 50 line in performance and the 110 just slaps the entire USG line up to the 2000 model. Even if the 110 had UTM features I bet it would still slap most the lineup, at the lowest model mind you.
 
Since this is the same person asking about web filtering in a newer post, I am going to recommend a ClearOS box to do both firewall and web filtering.
 
I've put the Zyxell ZYWALL110, Fortinet FortiGate-60D, and ClearOS on my bucket list.
 
Juniper SRX210 love, anyone ?

The Juniper Networks SRX210 Services Gateway offers complete functionality and flexibility for delivering secure and reliable data, along with multiple interfaces that support WAN and LAN connectivity and Power over Ethernet (PoE).

The SRX210 Services Gateway provides Internet Protocol Security (IPsec), virtual private network (VPN), and firewall services for small and medium-sized companies and enterprise branch and remote offices. Additional security features also include Unified Threat Management (UTM), which consists of IPS antispam, antivirus, and Web filtering

Not sure what the licensing fees run though.

Probably pretty spensive.
 
The SSG5s are bulletproof as well, but getting a bit long in the tooth like the 1st gen ASAs and I've found them somewhat limited in logging and troubleshooting.

Haven't played with any SRX equipment yet...
 
Does the Zyxell ZYWALL110 have built-in/support [paid/subscription/commercial] content filtering?

Between that and the Fortinet FortiGate-60D, which would serve better for web-filtering? I want to add an additional layer to OpenDNS and K9 Web Protection.

It's too hard/complicated/not straightforward on DD-WRT to restrict DNS down to nothing else but 208.67.220.123 and 208.67.222.123. :( Are either of the above easily able to accomplish that with minimal configuration/effort?

EDIT: Nevermind, managed to get DNS restriction working with ease! :) thx to http://www.dd-wrt.com/wiki/index.php/OpenDNS and http://www.quepublishing.com/articles/article.aspx?p=1314012&seqNum=4
 
Last edited:
Does the Zyxell ZYWALL110 have built-in/support [paid/subscription/commercial] content filtering?

Between that and the Fortinet FortiGate-60D, which would serve better for web-filtering? I want to add an additional layer to OpenDNS and K9 Web Protection.


Can't really compare the Fortinet with the ZyWall 110. The 110 is a solid Firewall only device (a fairly beefy, badass, well priced one). There are rumors that perhaps once the USG line gets updated this year, that a firmware update might add some of the USG line features, but I would take it with a grain of salt.

There is a possibility, but as of now it does not including anything outside of basic firewalling. Comparing the Fortinet line vs the ZyXel I don't think you can go wrong. The main thing that holds Fortinet products back is their customer service. A lot of people find that being the deal breaker compared to ZyXel's high class support.

If you ask me the best ZyXel line to shoot for would be the USG 100 Plus. Unique hardware more powerful than the normal line and comes with all the things you'd expect. I have no problems maxing out my 30/5 connection with the Firewall, ADP, IDP, and Content Filtering on. So if you were just doing Firewall/ADP/Content Filtering I don't think you'd take too much of a hit.
 
The thing about the Zyxel content filtering that always discouraged me was the lack of automatic authentication against AD.
 
Back
Top