Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 




Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Security and Firewalls
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Security and Firewalls Protecting you against unwanted people and programs


Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]
Reply
 
LinkBack Thread Tools
Old 10-18-2007, 07:18 AM   #1 (permalink)
Registered User
 
Join Date: Jan 2007
Location: Western PA
Posts: 386
OS: Vista x64


Good mid size company router/gateway ideas? VPN solutions (Ssl)? Current choices ...

We are researching replacing our existing (and frequently locking up) Symantec Gateway 460 gateway (was a $650 device). Currently it has the firewall and vpn built in (ipsec). This unit requires that end users use proprietary vpn software, rather than just creating a windows vpn connection.. this software doesnt work in x64 Vista (or Vista period). We also have installed pptp vpn on a backend server and use this as an alternate for now.

We have a 15 mbit Comcast cable connection (1mbit upload) and a 3mbit verizon connection (1mbit upload max).. We have about 10 users at the moment (out of 42) who use VPN, usually only about 3-4 at a time though.

I'd really like an all in one solution that was VPN SSL capable (i'm assuming this means the end user wouldnt need proprietary software, just an SSL certificate and a connection in most cases?).. but it seems most are breaking the two apart these days?

Here are my current choices.. any thoughts on these or perhaps others out there i haven't thought of? (perhaps cheaper ones that are just as good)? We need to have dual wan ability in either case though..

Gateways:

Sonicwall Pro 2040 Internet Security Appliance: (dual wan able) 01-SSC-5700 $1339.88 (24x7 support option 01-SSC-5707 = $350.97)
**No SSL vpn ability need separate unit, see below (has standard 10 license, ipsec vpn ability); 200mbps on firewall and 50mps on vpn

Juniper SSG-140-SH $2569
** 350mbps on firewall; 100 mbps on vpn



Secondary vpn device:
SonicWall SSL-VPN 2000 01-SSC-5952 $1691 (unlimited users)
*Nice interface via the web, does require a small app installed via the web to directly connect though.


Any thoughts?
markm75 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 10-22-2007, 04:26 PM   #2 (permalink)
Moderator Networking Team
 
Cellus's Avatar
 
Join Date: Aug 2006
Location: Canada
Posts: 2,664
OS: Windows Vista Business SP1, Windows XP Professional SP3

My System

Re: Good mid size company router/gateway ideas? VPN solutions (Ssl)? Current choices

SonicWALL makes some pretty decent firewalls and VPN products. Considering your current Internet throughput you don't really need the extra throughput capability of the Juniper gateway. It does admittedly come out as more expensive, but you certainly get your money's worth with their bigger 1U appliances. Just note that the documentation can bit slightly lacking at times, so you may need to fish around a bit if something isn't clearly explained in the manual.
__________________
TSF Networking Team

Virus/Trojan/Spyware Removal Help
Donate!
Cellus is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 10-25-2007, 07:29 PM   #3 (permalink)
Registered User
 
Join Date: Oct 2007
Location: new zealand
Posts: 1
OS: Windows XPSP2, SuSe, Solaris 10, Windows 2003, Ubuntu


Re: Good mid size company router/gateway ideas? VPN solutions (Ssl)? Current choices

Quote:
Originally Posted by markm75 View Post
We are researching replacing our existing (and frequently locking up) Symantec Gateway 460 gateway (was a $650 device). Currently it has the firewall and vpn built in (ipsec). This unit requires that end users use proprietary vpn software, rather than just creating a windows vpn connection.. this software doesnt work in x64 Vista (or Vista period). We also have installed pptp vpn on a backend server and use this as an alternate for now.

We have a 15 mbit Comcast cable connection (1mbit upload) and a 3mbit verizon connection (1mbit upload max).. We have about 10 users at the moment (out of 42) who use VPN, usually only about 3-4 at a time though.

I'd really like an all in one solution that was VPN SSL capable (i'm assuming this means the end user wouldnt need proprietary software, just an SSL certificate and a connection in most cases?).. but it seems most are breaking the two apart these days?

Here are my current choices.. any thoughts on these or perhaps others out there i haven't thought of? (perhaps cheaper ones that are just as good)? We need to have dual wan ability in either case though..

Gateways:

Sonicwall Pro 2040 Internet Security Appliance: (dual wan able) 01-SSC-5700 $1339.88 (24x7 support option 01-SSC-5707 = $350.97)
**No SSL vpn ability need separate unit, see below (has standard 10 license, ipsec vpn ability); 200mbps on firewall and 50mps on vpn

Juniper SSG-140-SH $2569
** 350mbps on firewall; 100 mbps on vpn



Secondary vpn device:
SonicWall SSL-VPN 2000 01-SSC-5952 $1691 (unlimited users)
*Nice interface via the web, does require a small app installed via the web to directly connect though.


Any thoughts?

Okay - SSL-VPN depending on your company security requirements & or complexity. I would advise against having your Firewall terminate your VPN sessions. instead deploy a SSL-VPN capable appliance. like a entry level F5 Firepass. Why? - hardware seperation will reduce the amount configuration required on your boundry firewall & simplify your rules... i.e bolting on a SSL-VPN service to the side in say a VPN Zone will allow you to create seperation from your Public or private DMZ area's. The will also allow to you to allow Frag IP to that Zone only. (assuming you choose the juniper the screening rules will need to be setup correctly)

Dependng also on your budget the Juniper looks like the best option, make sure you you get the latest ScreenOS installed.
Please note Juniper's can be tricky to configure & understand.

Indeed SSL-VPN can use HTTPS via Web browser - as well as a VPN Client.
wiccaman is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 10-25-2007, 07:56 PM   #4 (permalink)
Registered User
 
Join Date: Jan 2007
Location: Western PA
Posts: 386
OS: Vista x64


Re: Good mid size company router/gateway ideas? VPN solutions (Ssl)? Current choices

Quote:
Originally Posted by wiccaman View Post
Okay - SSL-VPN depending on your company security requirements & or complexity. I would advise against having your Firewall terminate your VPN sessions. instead deploy a SSL-VPN capable appliance. like a entry level F5 Firepass. Why? - hardware seperation will reduce the amount configuration required on your boundry firewall & simplify your rules... i.e bolting on a SSL-VPN service to the side in say a VPN Zone will allow you to create seperation from your Public or private DMZ area's. The will also allow to you to allow Frag IP to that Zone only. (assuming you choose the juniper the screening rules will need to be setup correctly)

Dependng also on your budget the Juniper looks like the best option, make sure you you get the latest ScreenOS installed.
Please note Juniper's can be tricky to configure & understand.

Indeed SSL-VPN can use HTTPS via Web browser - as well as a VPN Client.

I've been leaning more towards the Sonic wall model for the gateway.. and the 2000 series for VPN.. what do you think of these options? I figure the extra bandwidth of the juniper really doesnt help us much with our existing internet.. the 2000 for vpn makes more sense as it has many more features over the 200, including the netextender and java based rdp..
markm75 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 04:35 PM.



Copyright 2001 - 2010, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84