ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    SMB firewall options

    IT Discussion
    16
    57
    8.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bbigfordB
      bbigford @scottalanmiller
      last edited by

      @scottalanmiller said in SMB firewall options:

      @BBigford said in SMB firewall options:

      @zuphzuph said in SMB firewall options:

      Untangle. 😄

      You've gotten to mess with that more than I have. Have you checked out the content filtering and such? Does it have a VPN client? I couldn't remember if OpenVPN is available on that or if I'm thinking of pfSense...

      OpenVPN is on nearly everything.

      Then maybe I'm thinking of both. 😄

      scottalanmillerS 1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller @bbigford
        last edited by

        @BBigford said in SMB firewall options:

        @scottalanmiller said in SMB firewall options:

        @BBigford said in SMB firewall options:

        @zuphzuph said in SMB firewall options:

        Untangle. 😄

        You've gotten to mess with that more than I have. Have you checked out the content filtering and such? Does it have a VPN client? I couldn't remember if OpenVPN is available on that or if I'm thinking of pfSense...

        OpenVPN is on nearly everything.

        Then maybe I'm thinking of both. 😄

        EdgeOS and VyOS have it too.

        1 Reply Last reply Reply Quote 1
        • JaredBuschJ
          JaredBusch
          last edited by

          @BBigford and FFS you still have not answer this quesiton.

          @coliver said in SMB firewall options:

          So... are you looking for a firewall or a UTM?

          1 Reply Last reply Reply Quote 1
          • JaredBuschJ
            JaredBusch
            last edited by

            Because your title only says firewall. but you are talking about UTM stuff in your post.

            bbigfordB 1 Reply Last reply Reply Quote 3
            • bbigfordB
              bbigford @JaredBusch
              last edited by

              @JaredBusch said in SMB firewall options:

              Because your title only says firewall. but you are talking about UTM stuff in your post.

              Fixed. I know it's kind of apples to oranges since one includes the other and drives up the price substantially.

              scottalanmillerS 2 Replies Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @bbigford
                last edited by

                @BBigford said in SMB firewall/UTM options:

                @JaredBusch said in SMB firewall options:

                Because your title only says firewall. but you are talking about UTM stuff in your post.

                Fixed. I know it's kind of apples to oranges since one includes the other and drives up the price substantially.

                And generally we don't recommend UTMs. High cost, low results.

                bbigfordB 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @bbigford
                  last edited by

                  @BBigford said in SMB firewall/UTM options:

                  @JaredBusch said in SMB firewall options:

                  Because your title only says firewall. but you are talking about UTM stuff in your post.

                  Fixed. I know it's kind of apples to oranges since one includes the other and drives up the price substantially.

                  More like apples to bushels. They aren't different things, one is a big thing made up of the other.

                  1 Reply Last reply Reply Quote 2
                  • bbigfordB
                    bbigford @scottalanmiller
                    last edited by bbigford

                    @scottalanmiller said in SMB firewall options:

                    @BBigford said in SMB firewall/UTM options:

                    @JaredBusch said in SMB firewall options:

                    Because your title only says firewall. but you are talking about UTM stuff in your post.

                    Fixed. I know it's kind of apples to oranges since one includes the other and drives up the price substantially.

                    And generally we don't recommend UTMs. High cost, low results.

                    Fixed again. I'll just leave UTM out of it. I was talking with someone today about breaking out services since most UTMs I've used try to do everything in each category the best within one device, but seem to end up being mediocre in every area. Instead of just breaking out the services and focusing on one thing, and doing that one thing really well.

                    Until we got up into the +$20k UTMs. Then they were okay.

                    scottalanmillerS JaredBuschJ 2 Replies Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @bbigford
                      last edited by

                      @BBigford said in SMB firewall options:

                      @scottalanmiller said in SMB firewall options:

                      @BBigford said in SMB firewall/UTM options:

                      @JaredBusch said in SMB firewall options:

                      Because your title only says firewall. but you are talking about UTM stuff in your post.

                      Fixed. I know it's kind of apples to oranges since one includes the other and drives up the price substantially.

                      And generally we don't recommend UTMs. High cost, low results.

                      Fixed again. I'll just leave UTM out of it. I was talking with someone today about breaking out services since most UTMs I've used try to do everything in each category the best within one device, but seem to end up being mediocre in every area. Instead of just breaking out the services and focusing on one thing, and doing that one thing really well.

                      Without UTM, only Ubiquiti would be on my radar today.

                      1 Reply Last reply Reply Quote 1
                      • JaredBuschJ
                        JaredBusch @bbigford
                        last edited by JaredBusch

                        @BBigford said in SMB firewall options:

                        @scottalanmiller said in SMB firewall options:

                        @BBigford said in SMB firewall/UTM options:

                        @JaredBusch said in SMB firewall options:

                        Because your title only says firewall. but you are talking about UTM stuff in your post.

                        Fixed. I know it's kind of apples to oranges since one includes the other and drives up the price substantially.

                        And generally we don't recommend UTMs. High cost, low results.

                        Fixed again. I'll just leave UTM out of it. I was talking with someone today about breaking out services since most UTMs I've used try to do everything in each category the best within one device, but seem to end up being mediocre in every area. Instead of just breaking out the services and focusing on one thing, and doing that one thing really well.

                        Until we got up into the +$20k UTMs. Then they were okay.

                        Then if you are looking for a router only, go with EdgeMax as a baseline.

                        If those features are lacking move on from there.

                        stacksofplatesS 1 Reply Last reply Reply Quote 3
                        • gjacobseG
                          gjacobse @zuphzuph
                          last edited by

                          @zuphzuph said in SMB firewall options:

                          Untangle. 😄

                          There was a time that I would have suggested UT,.. and I have used it at two Non Profits without any issues.

                          @scottalanmiller has pointed me at laying off the UT bus and point more towards they true FW and I have installed a UBNT ERLite at home now. I've not spent a lot of time with it,.. but when my exposure with it in the Client field, the ER and ERL line work well.

                          And as mentioned - OpenVPN is on nearly everything. Even the ER line.

                          1 Reply Last reply Reply Quote 0
                          • JaredBuschJ
                            JaredBusch
                            last edited by

                            Untangle is fine if you want a massive AIO beast. I hate those though.

                            zuphzuphZ 1 Reply Last reply Reply Quote 1
                            • stacksofplatesS
                              stacksofplates @JaredBusch
                              last edited by

                              @JaredBusch said in SMB firewall options:

                              go with EdgeMax as a baseline

                              EdgeRouter X?

                              JaredBuschJ 1 Reply Last reply Reply Quote 0
                              • zuphzuphZ
                                zuphzuph Banned @JaredBusch
                                last edited by

                                @JaredBusch said in SMB firewall options:

                                Untangle is fine if you want a massive AIO beast. I hate those though.

                                Just out of curiosity, why?

                                JaredBuschJ 1 Reply Last reply Reply Quote 0
                                • JaredBuschJ
                                  JaredBusch @zuphzuph
                                  last edited by JaredBusch

                                  @zuphzuph said in SMB firewall options:

                                  @JaredBusch said in SMB firewall options:

                                  Untangle is fine if you want a massive AIO beast. I hate those though.

                                  Just out of curiosity, why?

                                  AIO are just bad in general.

                                  If you have 4 tasks that you need to do, separate them out unless there is a good benefit to keeping them AIO.

                                  1 Reply Last reply Reply Quote 1
                                  • JaredBuschJ
                                    JaredBusch @stacksofplates
                                    last edited by

                                    @stacksofplates said in SMB firewall options:

                                    @JaredBusch said in SMB firewall options:

                                    go with EdgeMax as a baseline

                                    EdgeRouter X?

                                    I would never use an ER-X for an office with more than 5 or 6 users. The ER-X does not have the balls for it.

                                    It is a great SOHO device.and handles that task well. For an office, I would always start with the ERL or ERPoE. Then move up to the ER-8 if needed.

                                    stacksofplatesS 1 Reply Last reply Reply Quote 4
                                    • stacksofplatesS
                                      stacksofplates @JaredBusch
                                      last edited by

                                      @JaredBusch said in SMB firewall options:

                                      @stacksofplates said in SMB firewall options:

                                      @JaredBusch said in SMB firewall options:

                                      go with EdgeMax as a baseline

                                      EdgeRouter X?

                                      I would never use an ER-X for an office with more than 5 or 6 users. The ER-X does not have the balls for it.

                                      It is a great SOHO device.and handles that task well. For an office, I would always start with the ERL or ERPoE. Then move up to the ER-8 if needed.

                                      I misunderstood what you were saying. I thought you were staying a certain model of theirs but you just meant the line with EdgeMax.

                                      1 Reply Last reply Reply Quote 0
                                      • wrx7mW
                                        wrx7m @scottalanmiller
                                        last edited by

                                        @scottalanmiller said in SMB firewall options:

                                        Only things I use anymore...

                                        • Ubiquit for nearly everything.
                                        • Sophos if they demand UTM but don't have the resources for the good stuff.
                                        • Palo Alto if they really need edge security.

                                        What would you consider "the good stuff" that you would use instead of Sophos UTM?

                                        JaredBuschJ 1 Reply Last reply Reply Quote 0
                                        • JaredBuschJ
                                          JaredBusch @wrx7m
                                          last edited by

                                          @wrx7m said in SMB firewall options:

                                          @scottalanmiller said in SMB firewall options:

                                          Only things I use anymore...

                                          • Ubiquit for nearly everything.
                                          • Sophos if they demand UTM but don't have the resources for the good stuff.
                                          • Palo Alto if they really need edge security.

                                          What would you consider "the good stuff" that you would use instead of Sophos UTM?

                                          Why do you mean? There are many pieces to an UTM.

                                          The FOSS pieces are readily available individually.

                                          wrx7mW 1 Reply Last reply Reply Quote 2
                                          • V
                                            Veet
                                            last edited by

                                            I think, for ~20 users, most of what you've listed would work (Although, I'm not a big fan of Cisco, and Watchguard)

                                            Apart from DNS services, I haven't used any Cloud based security service...

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 1 / 3
                                            • First post
                                              Last post