WUGNET, the Windows User Group Network
Your Complete Resource Center for "The Best" in Shareware, Computing Tips and Support, Windows Industry News... and much more!
Home Forums Shareware Windows Tips Hot Offers FREE Newsletters Arcade Contact Us About Partners
Search WUGNET: RSS Feeds RSS Feeds Advertise with WUGNET    |    Shareware eBooks
HomeHome FAQFAQ   SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log in/Register/PasswordLog in/Register/Password

Firewall recommendations

 
Goto page 1, 2
   Home -> Windows -> Security Admin RSS
Next:  Security Admin: Block ad sites with Hosts file - not working ?  
Author Message
Mha

External


Since: Dec 11, 2007
Posts: 9



(Msg. 1) Posted: Fri Aug 01, 2008 4:49 pm
Post subject: Firewall recommendations Add to elertz
Archived from groups: microsoft>public>windows>networking>firewall, others (more info?)

Hi

I'm looking for a 'blackbox' firewall solution for a small company about
50-60 users/computers with 4-5 servers (Web,Exchange,App server).
We also need one site-site VPN tunnel and client-site L2TP IPsec or maybe in
a future SSL vpn tunnels. I also need DNS and SMTP (proxy) on this box, to
use it as a mail-relay and DNS-relay from outside to our services into LAN.
Currently I'm looking WatchGuard FireBox X550e, it has all the
functionalities I need. Is this a good choice, or do you recommend any
other products that are more optimal for a small company
(price/performance). Maybe Netscreen or VigorPro, but I'm not sure if they
support DNS and SMTP proxy?
Thank you in advance!
Regards,
Miha
Back to top
Login to vote
void

External


Since: Dec 14, 2004
Posts: 4498



(Msg. 2) Posted: Fri Aug 01, 2008 4:49 pm
Post subject: Re: Firewall recommendations Add to elertz [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

In article <#CKGPX#8IHA.4088@TK2MSFTNGP03.phx.gbl>, miha.bernik RemoveThis @email.si
says...
> Hi
>
> I'm looking for a 'blackbox' firewall solution for a small company about
> 50-60 users/computers with 4-5 servers (Web,Exchange,App server).
> We also need one site-site VPN tunnel and client-site L2TP IPsec or maybe in
> a future SSL vpn tunnels. I also need DNS and SMTP (proxy) on this box, to
> use it as a mail-relay and DNS-relay from outside to our services into LAN.
> Currently I'm looking WatchGuard FireBox X550e, it has all the
> functionalities I need. Is this a good choice, or do you recommend any
> other products that are more optimal for a small company
> (price/performance). Maybe Netscreen or VigorPro, but I'm not sure if they
> support DNS and SMTP proxy?
> Thank you in advance!

I have Firebox X550e through 1250e units, more than 100 across the
country, and I've found that with the UTM package that they are better
than any other units I've used/tried or have installed that are not WG
units.

You can't go wrong with the X550e, and if they need more performance
it's a "soft-key" upgrade performance to the 7xx series.....

Why would you want to relay DNS to your lan? Not a good idea for any
network, at least not one that would have you posting to this group.

Your exchange service will be well protected if you setup the UTM
services on the firebox to clean email (in and/or out) of malware and
bad file types....

You can email me if you need help once you purchase it (removed the 999)
to reply (see sig for email address)

--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free RemoveThis @rrohio.com (remove 999 for proper email address)
Back to top
Login to vote
Mha

External


Since: Dec 11, 2007
Posts: 9



(Msg. 3) Posted: Fri Aug 01, 2008 8:48 pm
Post subject: Re: Firewall recommendations Add to elertz [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Thanks for informations.
I think that Firebox x550e will be exactly what we need for our company
(50-60 users)., I only plan to take LiveSeucirty subscription (not
UTM-Spam/Web/Gateway blocker), I think this will be sufficient for now,
we'll se in a future if we need these extra services. I also plan to buy
upgrade to FireFire Pro for more SSL VPN connection for my home users. I
need SMTP proxy so that Exchange server will relay through it (not to be
exposed to internet), also all mail from outside will be delivered to
FireBox that will forward it to Exchange server. Considering DNS proxy, I'm
thinking of using our internal DNS server also for DNS resolver from
internet, but also I don't want to expose it directly so it will be resolved
through FireBox proxy DNS,
Any other opinion or proposal about this configuration?
Regards,
Miha

"Leythos" <void DeleteThis @nowhere.lan> je napisal v sporocilo
news:1217614552_245384@news.usenet.com ...
> In article <#CKGPX#8IHA.4088@TK2MSFTNGP03.phx.gbl>, miha.bernik DeleteThis @email.si
> says...
>> Hi
>>
>> I'm looking for a 'blackbox' firewall solution for a small company about
>> 50-60 users/computers with 4-5 servers (Web,Exchange,App server).
>> We also need one site-site VPN tunnel and client-site L2TP IPsec or maybe
>> in
>> a future SSL vpn tunnels. I also need DNS and SMTP (proxy) on this box,
>> to
>> use it as a mail-relay and DNS-relay from outside to our services into
>> LAN.
>> Currently I'm looking WatchGuard FireBox X550e, it has all the
>> functionalities I need. Is this a good choice, or do you recommend any
>> other products that are more optimal for a small company
>> (price/performance). Maybe Netscreen or VigorPro, but I'm not sure if
>> they
>> support DNS and SMTP proxy?
>> Thank you in advance!
>
> I have Firebox X550e through 1250e units, more than 100 across the
> country, and I've found that with the UTM package that they are better
> than any other units I've used/tried or have installed that are not WG
> units.
>
> You can't go wrong with the X550e, and if they need more performance
> it's a "soft-key" upgrade performance to the 7xx series.....
>
> Why would you want to relay DNS to your lan? Not a good idea for any
> network, at least not one that would have you posting to this group.
>
> Your exchange service will be well protected if you setup the UTM
> services on the firebox to clean email (in and/or out) of malware and
> bad file types....
>
> You can email me if you need help once you purchase it (removed the 999)
> to reply (see sig for email address)
>
> --
> - Igitur qui desiderat pacem, praeparet bellum.
> - Calling an illegal alien an "undocumented worker" is like calling a
> drug dealer an "unlicensed pharmacist"
> spam999free DeleteThis @rrohio.com (remove 999 for proper email address)
Back to top
Login to vote
void

External


Since: Dec 14, 2004
Posts: 4498



(Msg. 4) Posted: Fri Aug 01, 2008 8:48 pm
Post subject: Re: Firewall recommendations Add to elertz [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

In article <#IGs9cA9IHA.4608@TK2MSFTNGP06.phx.gbl>, miha.bernik.DeleteThis@email.si
says...
> Thanks for informations.
> I think that Firebox x550e will be exactly what we need for our company
> (50-60 users)., I only plan to take LiveSeucirty subscription (not
> UTM-Spam/Web/Gateway blocker), I think this will be sufficient for now,
> we'll se in a future if we need these extra services.

UTM bundle CAN be cheaper if you get it with the firewall as a bundle
than just the firewall alone - check with your vendors. I can get a
x550e + UTM for about $1500 and the yearly renewal is a LOT cheaper than
on a 7xx or 12xx series.

The email anti-spam is on par as being the best I've ever used of any,
it's even proving to be better then the masses of GFI installations and
better than the two Trend installations we have. The only thing that
comes close is the Barracuda, in MY testing.

> I also plan to buy
> upgrade to FireFire Pro for more SSL VPN connection for my home users. I
> need SMTP proxy so that Exchange server will relay through it (not to be
> exposed to internet), also all mail from outside will be delivered to
> FireBox that will forward it to Exchange server.

Mail is not actually "Delivered" to the firebox, it passes through a
SMTP rule that acts as a proxy service, it will clean the SMTP content
and headers as you define in the rule.

> Considering DNS proxy, I'm
> thinking of using our internal DNS server also for DNS resolver from
> internet, but also I don't want to expose it directly so it will be resolved
> through FireBox proxy DNS,
> Any other opinion or proposal about this configuration?

There is NO REASON to have your server provide DNS outside the LAN,
none, and don't do it. Purchase cheap DNS service out side and let them
get hit by all of the attempts.

It's easy enough to mirror your external DNS and point the internal DNS
to your private or public addresses.

--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free.DeleteThis@rrohio.com (remove 999 for proper email address)
Back to top
Login to vote
Mha

External


Since: Dec 11, 2007
Posts: 9



(Msg. 5) Posted: Sat Aug 02, 2008 8:56 am
Post subject: Re: Firewall recommendations Add to elertz [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Thanks again for all the tips!
Yes you're right, taking UTM bundle for x550e (Firebox+Spam/Web/Gateway
blocker+LiveSecurity) costs in my country (Europe) about 3000$, just
Firebox alone costs 2500$, so for a 500$ I get 1-year full subscription to
all services, and next year we'll decide if we extend subscription.
So I think for now FireBox x550e UTM bundle + Fireware PRO will be the right
choice. I'll let you know more when I get the equipment.
Thanks again!
Regards,
Miha


"Leythos" <void.TakeThisOut@nowhere.lan> je napisal v sporocilo
news:1217625192_245397@news.usenet.com ...
> In article <#IGs9cA9IHA.4608@TK2MSFTNGP06.phx.gbl>, miha.bernik.TakeThisOut@email.si
> says...
>> Thanks for informations.
>> I think that Firebox x550e will be exactly what we need for our company
>> (50-60 users)., I only plan to take LiveSeucirty subscription (not
>> UTM-Spam/Web/Gateway blocker), I think this will be sufficient for now,
>> we'll se in a future if we need these extra services.
>
> UTM bundle CAN be cheaper if you get it with the firewall as a bundle
> than just the firewall alone - check with your vendors. I can get a
> x550e + UTM for about $1500 and the yearly renewal is a LOT cheaper than
> on a 7xx or 12xx series.
>
> The email anti-spam is on par as being the best I've ever used of any,
> it's even proving to be better then the masses of GFI installations and
> better than the two Trend installations we have. The only thing that
> comes close is the Barracuda, in MY testing.
>
>> I also plan to buy
>> upgrade to FireFire Pro for more SSL VPN connection for my home users. I
>> need SMTP proxy so that Exchange server will relay through it (not to be
>> exposed to internet), also all mail from outside will be delivered to
>> FireBox that will forward it to Exchange server.
>
> Mail is not actually "Delivered" to the firebox, it passes through a
> SMTP rule that acts as a proxy service, it will clean the SMTP content
> and headers as you define in the rule.
>
>> Considering DNS proxy, I'm
>> thinking of using our internal DNS server also for DNS resolver from
>> internet, but also I don't want to expose it directly so it will be
>> resolved
>> through FireBox proxy DNS,
>> Any other opinion or proposal about this configuration?
>
> There is NO REASON to have your server provide DNS outside the LAN,
> none, and don't do it. Purchase cheap DNS service out side and let them
> get hit by all of the attempts.
>
> It's easy enough to mirror your external DNS and point the internal DNS
> to your private or public addresses.
>
> --
> - Igitur qui desiderat pacem, praeparet bellum.
> - Calling an illegal alien an "undocumented worker" is like calling a
> drug dealer an "unlicensed pharmacist"
> spam999free.TakeThisOut@rrohio.com (remove 999 for proper email address)
Back to top
Login to vote
void

External


Since: Dec 14, 2004
Posts: 4498



(Msg. 6) Posted: Sat Aug 02, 2008 9:58 am
Post subject: Re: Firewall recommendations Add to elertz [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

In article <uIPHrzG9IHA.5556 RemoveThis @TK2MSFTNGP02.phx.gbl>, miha.bernik RemoveThis @email.si
says...
> Thanks again for all the tips!
> Yes you're right, taking UTM bundle for x550e (Firebox+Spam/Web/Gateway
> blocker+LiveSecurity) costs in my country (Europe) about 3000$, just
> Firebox alone costs 2500$, so for a 500$ I get 1-year full subscription to
> all services, and next year we'll decide if we extend subscription.
> So I think for now FireBox x550e UTM bundle + Fireware PRO will be the right
> choice. I'll let you know more when I get the equipment.
> Thanks again!
> Regards,

If you've never setup a firewall, a real one, then you will want to
consider a lot of things - like what traffic to let out, what to let in,
etc....

Some things I've found, when you get it setup you're going to end up
with about 25-35 rules, the default is to allow all outbound, but block
certain ports and actions, I never leave an generic Outbound rule in
place.

You will need rules for the following:

FTP-Proxy.IN
FTP-Proxy.Out
SMTP-Proxy.IN
SMTP-Proxy.Out
HTTP-Proxy.NO-WEB-BLOCKER.Out (for your servers)
HTTP-Proxy.Web-Blocker.Out (for most users)
HTTP-Proxy.In (for your web servers if you have any)
POP3-Proxy.Out (if you have any pop3 users/accouns)
NNTP.Out
HTTPS.In (for your servers if needed)
HTTPS-Proxy.Out
Ping.Out
Time.Out
NTP.Out
PPTP.Out (if you allow this)
RWW.In (RWW ports if you use Small Business Server) TCP 4125/444
Traceroute.Out

Then you will have a lot of rules for other things that are not just the
basics - like VNC outbound, RDP outbound or inbound....

One thing to remember - the default SMTP filter removes characters from
email addresses, it will remove a decimal point by default, so you need
to remove that part of the rule to allow email addresses with names like
someone.lastname RemoveThis @somewhere.com.... It would remove the . between someone
and lastname but not the .com one.


--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free RemoveThis @rrohio.com (remove 999 for proper email address)
Back to top
Login to vote
Miha

External


Since: Oct 23, 2005
Posts: 47



(Msg. 7) Posted: Mon Aug 04, 2008 12:20 pm
Post subject: Re: Firewall recommendations Add to elertz [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Thanks. I'm quite familiar with rules on firewall, but don't have any
experiences with WatchGuard. Thank you again for all informations, I'll try
to configure it, we'll see how will it go.
Regards,
Miha

"Leythos" <void DeleteThis @nowhere.lan> wrote in message
news:1217692603_245455@news.usenet.com...
> In article <uIPHrzG9IHA.5556 DeleteThis @TK2MSFTNGP02.phx.gbl>, miha.bernik DeleteThis @email.si
> says...
>> Thanks again for all the tips!
>> Yes you're right, taking UTM bundle for x550e (Firebox+Spam/Web/Gateway
>> blocker+LiveSecurity) costs in my country (Europe) about 3000$, just
>> Firebox alone costs 2500$, so for a 500$ I get 1-year full subscription
>> to
>> all services, and next year we'll decide if we extend subscription.
>> So I think for now FireBox x550e UTM bundle + Fireware PRO will be the
>> right
>> choice. I'll let you know more when I get the equipment.
>> Thanks again!
>> Regards,
>
> If you've never setup a firewall, a real one, then you will want to
> consider a lot of things - like what traffic to let out, what to let in,
> etc....
>
> Some things I've found, when you get it setup you're going to end up
> with about 25-35 rules, the default is to allow all outbound, but block
> certain ports and actions, I never leave an generic Outbound rule in
> place.
>
> You will need rules for the following:
>
> FTP-Proxy.IN
> FTP-Proxy.Out
> SMTP-Proxy.IN
> SMTP-Proxy.Out
> HTTP-Proxy.NO-WEB-BLOCKER.Out (for your servers)
> HTTP-Proxy.Web-Blocker.Out (for most users)
> HTTP-Proxy.In (for your web servers if you have any)
> POP3-Proxy.Out (if you have any pop3 users/accouns)
> NNTP.Out
> HTTPS.In (for your servers if needed)
> HTTPS-Proxy.Out
> Ping.Out
> Time.Out
> NTP.Out
> PPTP.Out (if you allow this)
> RWW.In (RWW ports if you use Small Business Server) TCP 4125/444
> Traceroute.Out
>
> Then you will have a lot of rules for other things that are not just the
> basics - like VNC outbound, RDP outbound or inbound....
>
> One thing to remember - the default SMTP filter removes characters from
> email addresses, it will remove a decimal point by default, so you need
> to remove that part of the rule to allow email addresses with names like
> someone.lastname DeleteThis @somewhere.com.... It would remove the . between someone
> and lastname but not the .com one.
>
>
> --
> - Igitur qui desiderat pacem, praeparet bellum.
> - Calling an illegal alien an "undocumented worker" is like calling a
> drug dealer an "unlicensed pharmacist"
> spam999free DeleteThis @rrohio.com (remove 999 for proper email address)
Back to top
Login to vote
void

External


Since: Dec 14, 2004
Posts: 4498



(Msg. 8) Posted: Mon Aug 04, 2008 12:20 pm
Post subject: Re: Firewall recommendations Add to elertz [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

In article <OjiWpuh9IHA.2336.DeleteThis@TK2MSFTNGP03.phx.gbl>, miha.bernik.DeleteThis@email.si
says...
> Thanks. I'm quite familiar with rules on firewall, but don't have any
> experiences with WatchGuard. Thank you again for all informations, I'll try
> to configure it, we'll see how will it go.
> Regards,

If you run into trouble with it and want help, either contact me by
email or post here - make sure that you include the word WATCHGUARD or
FIREWALL in your subject, I look for key words and don't see posters
names when scanning threads.

--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free.DeleteThis@rrohio.com (remove 999 for proper email address)
Back to top
Login to vote
Display posts from previous:   
       Home -> Windows -> Security Admin All times are: Eastern Time (US & Canada) (change)
Goto page 1, 2
Page 1 of 2

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum
Categories:
  Windows XP
 Windows Vista
 Windows Other
 Office
 Office Other
 Security
 WinRAR
  • Home |
  • Shareware |
  • Windows Tips |
  • Hot Offers |
  • FREE Newsletters |
  • Arcade |
  • Forums |
  • eBooks |
  • About WUGNET |
  • Partners |
  • Contact

  • WUGNET Privacy Policy |
  • Link to WUGNET