Registered users    
MembershipMembership:
Latest New UserLatest:Mark Ellis
New TodayNew Today:9
New YesterdayNew Yesterday:7
User CountOverall:23403

Private messaging    
You must be logged in to use this module.
Top 10 posters    
NamePosts
Mariette Knap12957
Marina Roos12627
Eriq Neale2117
Stan Guinn1917
Michael Patrick1914
Robert Pearman1786
Nick Pieters1425
william warren641
Stewart Brown620
Kevin D.579
Welcome unauthorized visitor    
If you want to join us in the discussions on this forum you need to register first. Registration is free! If you are already a registered user please login to join the forum.
Small Business Server Support Forum    
Subject: Firewall Recommendation
Prev Next
You are not authorized to post a reply.

Author Messages
Steve Moss User is Offline
Telford, U.K.
Member since
8/30/2006

Registered Users
Posts: 115

7/14/2008 02:19 PM  
I'm looking for an external firewall recommendation for a client who wishes to support both a (small) SBS LAN and a separate guest VLAN, for both Ethernet and WiFi access. The firewall should provide VLAN support, multiple-SSID WiFi and DHCP for the guest VLAN, but not the SBS LAN. My full list of requirements is given below.
 
It is easy enough to fulfill all the requirements with multiple devices (with a separate WiFi router for the guest VLAN, hung off the main firewall), but the client would like to minimize number of the WiFi signals (hence the need for a single device with multiple WiFi SSID support).
 
The problem is that most firewall vendors' sites do not contain sufficient detail to make an informed decision, so I am looking for other people's experiences with various devices. Here is the full list of requirements:
  • Dual WAN ports (either 1 ADSL and 1 Ethernet, or both Ethernet), with load-balancing and/or fail-over.
  • SPI, DoS defence and NAT (with port forwarding, DMZ).
  • At least one GB Ethernet port, preferably more (but one GB with 3 10/100 ports will suffice).
  • VLANs (port-based and WiFi VLAN and/or separation).
  • WiFi g/n, with multiple SSID support.
  • Different security per SSID: WPA/2 + RADIUS for SBS LAN, WPA/2-PSK, etc.
  • Dual subnets, with Dual DHCP servers that can be allotted to VLANs.
  • VPN support: site-to-site, PPTP, L2TP/IPSec, pass-through. 5 tunnels should suffice.
VoIP (SP) support would be a nice-to-have, but optional, as would QoS. I'm not looking for a UTM device at this time. Any feedback will be appreciated. TIA.
Kevin Da Silva User is Offline
Mississauga, Canada
Member since
1/12/2008

Registered Users
Posts: 579

7/14/2008 09:53 PM  
Well I have been using Watchguard for a while now I am using the Firebox x550e it can handle pretty much all those requests other than the Wifi, but I do know they make some Wifi products, you should check those out or the Firebox, works well and suports Dual WAN.

MCSE:Messaging, MCTIP, SBS Specialist
william warren User is Offline
United States
Member since
12/8/2005

Registered Users
Posts: 641

7/15/2008 04:55 AM  
if you want to separate the wifi out to it's own box that hooks into a server take a look at astaro. it will handle everything except self-contained wifi BUT you can hook it up to another nic on the server and perform the functions needed.

Registered Microsoft Partner
Steve Moss User is Offline
Telford, U.K.
Member since
8/30/2006

Registered Users
Posts: 115

8/03/2008 01:01 PM  
Thanks guys - your responses are appreciated.
william warren User is Offline
United States
Member since
12/8/2005

Registered Users
Posts: 641

8/09/2008 04:00 AM  
Posted By william warren on 7/15/2008 04:55 AM
if you want to separate the wifi out to it's own box that hooks into a server take a look at astaro. it will handle everything except self-contained wifi BUT you can hook it up to another nic on the server and perform the functions needed.
Let me redo my recommendation..use untangle or ipcop.

Registered Microsoft Partner
You are not authorized to post a reply.



ActiveForums 3.7
Forum policy    
These Discussion Forums are dedicated to the discussion of the Small Business Server and related server and client software. For the benefit of the community please observe the following posting guidelines:
  1. No Advertising. This includes promotion of commercial products and non-commercial products which are not directly related to Small Business Server and related server and client software.
  2. No Flaming or Trolling.
  3. No Profanity, Racism, or Prejudice.
  4. Site Moderators have the final word on approving/removing a thread or post or comment.