ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Virtual Firewall

    Scheduled Pinned Locked Moved IT Discussion
    19 Posts 5 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @Jimmy9008
      last edited by

      @jimmy9008 said in Virtual Firewall:

      Sophos look to do a free virtual firewall 'Sophos UTM Essential Firewall' - anybody used it? Thoughts?

      Last I knew, only for home use.

      1 Reply Last reply Reply Quote 1
      • scottalanmillerS
        scottalanmiller @Jimmy9008
        last edited by

        @jimmy9008 said in Virtual Firewall:

        Sophos look to do a free virtual firewall 'Sophos UTM Essential Firewall' - anybody used it? Thoughts?

        Also, that's a UTM.

        1 Reply Last reply Reply Quote 1
        • scottalanmillerS
          scottalanmiller @Jimmy9008
          last edited by

          @jimmy9008 said in Virtual Firewall:

          @scottalanmiller said in Virtual Firewall:

          What's the goal? Why two firewalls? This isn't something that you normally want, unless this is to create an old fashioned full on DMZ.

          VyOS would be the main choice for something like this.

          WatchGuard have a bug in thier firmware which is holding us back from using thier M300 firewall in the way we want. Specifically, issues with their content action functionality and proxying the traffic. We plan to either move away from WatchGuard entirely (staged by having these two firewalls initially), or split the services until the bug is resolved (no timeline for that currently).

          The M300 will have our 1 Gigabit WAN. The virtual firewall will route out via our 100 Megabit WAN for specific servers only.

          Those are all UTM features, not firewall features. I have a suspicion that you are looking for a UTM, not a firewall. Or possibly that you are looking for UTM functionality, not firewall functionality, behind a firewall, which is a great way to go if you need that stuff. But using the wrong words so we are giving bad info to you, if so.

          J 1 Reply Last reply Reply Quote 1
          • J
            Jimmy9008 @scottalanmiller
            last edited by

            @scottalanmiller said in Virtual Firewall:

            @jimmy9008 said in Virtual Firewall:

            @scottalanmiller said in Virtual Firewall:

            What's the goal? Why two firewalls? This isn't something that you normally want, unless this is to create an old fashioned full on DMZ.

            VyOS would be the main choice for something like this.

            WatchGuard have a bug in thier firmware which is holding us back from using thier M300 firewall in the way we want. Specifically, issues with their content action functionality and proxying the traffic. We plan to either move away from WatchGuard entirely (staged by having these two firewalls initially), or split the services until the bug is resolved (no timeline for that currently).

            The M300 will have our 1 Gigabit WAN. The virtual firewall will route out via our 100 Megabit WAN for specific servers only.

            Those are all UTM features, not firewall features. I have a suspicion that you are looking for a UTM, not a firewall. Or possibly that you are looking for UTM functionality, not firewall functionality, behind a firewall, which is a great way to go if you need that stuff. But using the wrong words so we are giving bad info to you, if so.

            Any examples of virtual UTM devices in that case?

            scottalanmillerS 1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @Jimmy9008
              last edited by

              @jimmy9008 said in Virtual Firewall:

              @scottalanmiller said in Virtual Firewall:

              @jimmy9008 said in Virtual Firewall:

              @scottalanmiller said in Virtual Firewall:

              What's the goal? Why two firewalls? This isn't something that you normally want, unless this is to create an old fashioned full on DMZ.

              VyOS would be the main choice for something like this.

              WatchGuard have a bug in thier firmware which is holding us back from using thier M300 firewall in the way we want. Specifically, issues with their content action functionality and proxying the traffic. We plan to either move away from WatchGuard entirely (staged by having these two firewalls initially), or split the services until the bug is resolved (no timeline for that currently).

              The M300 will have our 1 Gigabit WAN. The virtual firewall will route out via our 100 Megabit WAN for specific servers only.

              Those are all UTM features, not firewall features. I have a suspicion that you are looking for a UTM, not a firewall. Or possibly that you are looking for UTM functionality, not firewall functionality, behind a firewall, which is a great way to go if you need that stuff. But using the wrong words so we are giving bad info to you, if so.

              Any examples of virtual UTM devices in that case?

              Sophos, Palo Alto, Untangle, etc.

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                VyOS is NOT a UTM, for example, but is the best firewall of the bunch. So an important differentiation.

                1 Reply Last reply Reply Quote 1
                • scottalanmillerS
                  scottalanmiller
                  last edited by

                  If doing this, I'd recommend moving to Ubiquiti for your actual firewall, no upside to anything else in this range. Ubiquiti is the best.

                  Then the UTM VM for all those other functions. Or it can be multiple VMs, no reason to have all the functions in one. Like web proxy and AV could be two different VMs from different vendors, in theory.

                  J 1 Reply Last reply Reply Quote 0
                  • J
                    Jimmy9008 @scottalanmiller
                    last edited by

                    @scottalanmiller said in Virtual Firewall:

                    If doing this, I'd recommend moving to Ubiquiti for your actual firewall, no upside to anything else in this range. Ubiquiti is the best.

                    Then the UTM VM for all those other functions. Or it can be multiple VMs, no reason to have all the functions in one. Like web proxy and AV could be two different VMs from different vendors, in theory.

                    If that UTM function is being handed over to the VM, why not keep M300 as the actual firewall which has not been the problem? The firewall part of the M300 has been great, its the UTM feature that i'd look to me moving off to the VM.

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @Jimmy9008
                      last edited by

                      @jimmy9008 said in Virtual Firewall:

                      @scottalanmiller said in Virtual Firewall:

                      If doing this, I'd recommend moving to Ubiquiti for your actual firewall, no upside to anything else in this range. Ubiquiti is the best.

                      Then the UTM VM for all those other functions. Or it can be multiple VMs, no reason to have all the functions in one. Like web proxy and AV could be two different VMs from different vendors, in theory.

                      If that UTM function is being handed over to the VM, why not keep M300 as the actual firewall which has not been the problem? The firewall part of the M300 has been great, its the UTM feature that i'd look to me moving off to the VM.

                      Just to make it easier to save money and unify management long term. It would be no rush, but at least make the plans now. You don't want to end up in a spot where the Watchguard gets replaced with something else incredibly silly later on. Sometimes it's worth investing well now (we are talking like $85) to make sure the right stuff is in place so that expensive stuff doesn't get bought again down the road.

                      1 Reply Last reply Reply Quote 0
                      • J
                        Jimmy9008
                        last edited by

                        @scottalanmiller said in Virtual Firewall:

                        @jimmy9008 said in Virtual Firewall:

                        @scottalanmiller said in Virtual Firewall:

                        If doing this, I'd recommend moving to Ubiquiti for your actual firewall, no upside to anything else in this range. Ubiquiti is the best.

                        Then the UTM VM for all those other functions. Or it can be multiple VMs, no reason to have all the functions in one. Like web proxy and AV could be two different VMs from different vendors, in theory.

                        If that UTM function is being handed over to the VM, why not keep M300 as the actual firewall which has not been the problem? The firewall part of the M300 has been great, its the UTM feature that i'd look to me moving off to the VM.

                        Just to make it easier to save money and unify management long term. It would be no rush, but at least make the plans now. You don't want to end up in a spot where the Watchguard gets replaced with something else incredibly silly later on. Sometimes it's worth investing well now (we are talking like $85) to make sure the right stuff is in place so that expensive stuff doesn't get bought again down the road.

                        Yes, that makes sense. Other things in the pipeling will take priority over this currently though. Will add to investigate this to my list. Ta Scott.

                        1 Reply Last reply Reply Quote 1
                        • ObsolesceO
                          Obsolesce @scottalanmiller
                          last edited by

                          @scottalanmiller said in Virtual Firewall:

                          Why two firewalls?

                          DMZ --> Perimeter Network --> LAN?

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Obsolesce
                            last edited by

                            @tim_g said in Virtual Firewall:

                            @scottalanmiller said in Virtual Firewall:

                            Why two firewalls?

                            DMZ --> Perimeter Network --> LAN?

                            That's how it used to be. The DMZ meant the area between the firewalls.

                            1 Reply Last reply Reply Quote 0
                            • 1 / 1
                            • First post
                              Last post