Fires of Heaven Guild Message Board  

Go Back   Fires of Heaven Guild Message Board > General forums > General
User Name
Password
ForumSpy Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 10-12-2006, 08:08 PM   #1 (permalink)
Jaytee Bushwacker
FoH Member with a rod in his pants
 
Jaytee Bushwacker's Avatar
 
Join Date: Jan 2002
Location: Forest, MS
Posts: 243
+0 Internets
Anyone worked with Cisco PIX's before

I got one and I'm wanting to use it to replace my Cyberguard firewall. I was wondering if anyone here had any experience with them and I could ask a couple questions of via PM.
__________________
Jaytee Bushwacker is offline   Reply With Quote
Old 10-13-2006, 02:52 AM   #2 (permalink)
woot!
Jesus with laser
 
woot!'s Avatar
 
Join Date: Apr 2003
Posts: 533
+8 Internets
Honestly, PIX is shit.

If you want to replace your firewalls, look for the Juniper Netscreen products. I have been working with them for about 5 years now, and I am very happy about it.
They are reliable, and quite easy to configure and maintain.
There is a lot of documentation, lots of exemples, and their customer support is good.
Their products range from quite small firewalls (NS5GT) to the large company/provider equipment (NS5200/5400)
Here is a brief listing of their firewalls with some basic infos :
https://www.juniper.net/products/integrated/

***edit : When I say Pix is shit, I do not just say it out of the blue, but as a comparaison to the Netscreen products. I have worked with Pix firewalls quite a few times, and thought it was terrible.
__________________
Praise Xenu

Last edited by woot! : 10-13-2006 at 03:05 AM.
woot! is offline   Reply With Quote
Old 10-14-2006, 02:12 AM   #3 (permalink)
Taehoon
Banned
 
Join Date: Jul 2002
Posts: 518
+0 Internets
Whatever you do, stay away from Sonicwall's TZ170. Good concept, terrible implementation, and the support is horrid.

BTW, do the Netscreens do Inbound/Outbound bandwidth management? That was one of the features that the TZ170 had going for it; bandwidth management has it's uses, especially today when you're a small business using 1 connection to run everything, including hosting for multiple clients of several services.
Taehoon is offline   Reply With Quote
Old 10-14-2006, 04:51 AM   #4 (permalink)
Scape667
Unregistered User
 
Join Date: Jul 2003
Posts: 150
+0 Internets
Screw both of those get a Fortigate.
__________________
Good bye.
Scape667 is offline   Reply With Quote
Old 10-14-2006, 05:11 AM   #5 (permalink)
Ham n Cheese
You can betray me
 
Ham n Cheese's Avatar
 
Join Date: Dec 2002
Location: Houston
Posts: 8,667
+20 Internets
Send a message via AIM to Ham n Cheese Send a message via MSN to Ham n Cheese
I've used the PIX and am close to someone who sales them reguarly along with the TZ170 from sonicwall. I just replaced our pix at my work.
__________________



Xeph

Caito Cao'Li

Hunky Dory

Ham n Cheese is offline   Reply With Quote
Old 10-14-2006, 06:02 PM   #6 (permalink)
Jaytee Bushwacker
FoH Member with a rod in his pants
 
Jaytee Bushwacker's Avatar
 
Join Date: Jan 2002
Location: Forest, MS
Posts: 243
+0 Internets
Well I own the PIX and I got it in trade for some service work so I probably am going to stick with it for now. Port forwarding is a bitch on it though...the Cyberguard was real easy...pick the port, incomming interface, then pick the destination port/interface and done.

Access lists and more for the PIX. So any of ya mind if I ask about them in PMs?
__________________
Jaytee Bushwacker is offline   Reply With Quote
Old 10-16-2006, 09:30 PM   #7 (permalink)
Ham n Cheese
You can betray me
 
Ham n Cheese's Avatar
 
Join Date: Dec 2002
Location: Houston
Posts: 8,667
+20 Internets
Send a message via AIM to Ham n Cheese Send a message via MSN to Ham n Cheese
You can try and ask me. I might be able to help
__________________



Xeph

Caito Cao'Li

Hunky Dory

Ham n Cheese is offline   Reply With Quote
Old 10-17-2006, 03:15 AM   #8 (permalink)
woot!
Jesus with laser
 
woot!'s Avatar
 
Join Date: Apr 2003
Posts: 533
+8 Internets
Quote:
Originally Posted by Taehoon
BTW, do the Netscreens do Inbound/Outbound bandwidth management? That was one of the features that the TZ170 had going for it; bandwidth management has it's uses, especially today when you're a small business using 1 connection to run everything, including hosting for multiple clients of several services.
Yes, you can assign a certain amount of bandwith to a policy, you can set a guaranteed bw, and the priority of it.
For exemple, you can define that your ssh connexion going through the vpn tunnel set up with office #2 have highest priority, and that 128k of your bandwith will be reserved for it no matter what. Then that all the outgoing http traffic towards the internet has lowest priority compared to the rest of the traffic, apart from http connexions coming from your sales's dept subnet going to your company's website that would have a bit higher priority.
__________________
Praise Xenu
woot! is offline   Reply With Quote
Old 10-18-2006, 07:14 PM   #9 (permalink)
Jaytee Bushwacker
FoH Member with a rod in his pants
 
Jaytee Bushwacker's Avatar
 
Join Date: Jan 2002
Location: Forest, MS
Posts: 243
+0 Internets
About the PIX...I am thinking I need an access-list like this

ip access-list 100 permit tcp any 192.168.1.100 eq 3389

apply it to the outside interface like this

config-if# ip access-group 100 in


now for the reverse so traffic flows back out

ip access-list 101 permit tcp 192.168.1.100 any eq 3389

apply to the internal interface

config-if# ip access-group 101 out


Any ideas if thats the way to do it?
__________________
Jaytee Bushwacker is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On
uberguilds network



All times are GMT -7. The time now is 07:32 AM.


Powered by vBulletin® Version 3.6.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.0.0 RC6