Recommended Posts

^ yeah its hard to beat pfsense for "cost" FREE, you just need to provide some hardware to run it on and some setup time.

It will run on pretty much anything, you have a old pc around? There you go - your hardware.

  • Like 2

Any Cisco ISR will do this. But honestly you should be looking for a combined device with a NIPS, Malware filtering go incoming downloads aswell as the bog standard stateful firewall.

As always its the rules that matter and unless its set to implicit deny its worthless.

A issue also with pFsense is that other people in the office mostly know how to control it....With most common routers, this is possible With pFsense you have to take 10 minutes.

If you don't give them the admin password they will not be able to control it.

  • Like 2

dude I have been trying to help him in the other thread he has started.. If your not talking a 150 router its going to be over budget. Reread what he posted - he wants the other others to be able to control it.

He has no concern with content filtering, talk of SNORT - you might as well be talking talking nuclear physics to a 3 year old.

His clients ask his 10 year old zyxel for dns, and they are members of domain - I would bet this is 99% of his issues. The router his looking for is something you would pick up at your computer store for $20, not a SMB/Enterprise class firewall.

"A issue also with pFsense is that other people in the office mostly know how to control it....With most common routers, this is possible With pFsense you have to take 10 minutes."

I don't get it. It's a problem when people know how to control it? It takes a whopping 10 min to look at the GUI to figure it out? To me, it sounds like he doesn't want them to be able to figure it out and it is a problem if they can.

I don't think english is his native language.. screen shots of machines are in spanish I believe.

Notice the "With pFsense you have to take 10 minutes." - and in his other thread he clearly states that he looked at pfsense but it was too complicated ;)

"A way better firewall; pFsense seems complicated so Im thinking Cisco or DD-WRT."

So I take it he wants the office to be able to understand the router, not the other way around.

pFSense.. it is free.. I am sure you have some old hardware you can put it on.. I am not sure why you would want the whole office to use it..? They'll just have that crap shredded to pieces.. Sonicwalls are ok for the money.. you get what you pay for in that aspect.. If you are dead set against doing what most of everyone here is recommending.. look into getting a nice Cisco Router and loading DD-WRT

Let's be real for a second. Unless you're doing Site to Site VPNs, or need a remote access VPN for mobile users, then you might want to consider keeping a simple router setup. You really aren't going to find a "real" firewall that Joe Enduser can understand and operate. NAT, PAT, and VPN cryptography isn't something even the normal "admin" understands. This is just a pill that has to be swallowed. They might be able to set up users or something for remote access, but everything else should probably be left alone. If they don't then who do you think they will end up calling for help?

That being said. If a true firewall solution is what's needed, then if you have the knowledge (and believe me it takes a good bit) then a Cisco ASA 5505 is going to be about the best you can get for a very small office or a spoke site. If the learning curve is to great, then go with SonicWall gear, as others have mentioned. Either way you go, make sure that (as with all technology implemented in a production/business environment) you get a support contract, to get updates/assistance etc.

Don't waste time on unsupported freeware products. Not only is this very unwise, but you'll find yourself tearing all of them out if a merger ever happens because they aren't "standard" gear that most companies use.

Let's be real for a second. Unless you're doing Site to Site VPNs, or need a remote access VPN for mobile users, then you might want to consider keeping a simple router setup. You really aren't going to find a "real" firewall that Joe Enduser can understand and operate. NAT, PAT, and VPN cryptography isn't something even the normal "admin" understands. This is just a pill that has to be swallowed. They might be able to set up users or something for remote access, but everything else should probably be left alone. If they don't then who do you think they will end up calling for help?

That being said. If a true firewall solution is what's needed, then if you have the knowledge (and believe me it takes a good bit) then a Cisco ASA 5505 is going to be about the best you can get for a very small office or a spoke site. If the learning curve is to great, then go with SonicWall gear, as others have mentioned. Either way you go, make sure that (as with all technology implemented in a production/business environment) you get a support contract, to get updates/assistance etc.

Don't waste time on unsupported freeware products. Not only is this very unwise, but you'll find yourself tearing all of them out if a merger ever happens because they aren't "standard" gear that most companies use.

I don't see how you think PFSense, Smoothwall, Monowall, Untangle, etc, aren't REAL firewalls? I agree they aren't at the same level of an ASA, but there is nothing wrong with them. I know a LOT of businesses that use PFSense. For one thing, to get any support with the ASA (including downloads for upgraded firmware), then that will be more money.

For that matter, most of those firewalls have support options available, either through them or someone else. You also don't need a support contract. Just pay when you need it from one of those companies or vendors.

If you can't figure out PFSense, or any other firewall, an ASA isn't going to be any easier.

I don't see how you think PFSense, Smoothwall, Monowall, Untangle, etc, aren't REAL firewalls? I agree they aren't at the same level of an ASA, but there is nothing wrong with them. I know a LOT of businesses that use PFSense. For one thing, to get any support with the ASA (including downloads for upgraded firmware), then that will be more money.

For that matter, most of those firewalls have support options available, either through them or someone else. You also don't need a support contract. Just pay when you need it from one of those companies or vendors.

If you can't figure out PFSense, or any other firewall, an ASA isn't going to be any easier.

I didn't say that the ASA was the most "simple" solution, nor the most cost effective. I agree that it's quite the opposite. Just saying that amongst most large enterprises it's what I see the most of. If you have the knowledge, you can get a 5505 going for < $1000.

If I couldn't go the ASA route, then I wouldn't hesitate going SonicWall simply because of the quality support and also due to the fact that most enterprise level engineers are familiar with them.

If someone calls me in the middle of the night for a support call, and I have to tunnel into some homebrew PFSense box, then the first thing that pops in my head before I VPN to the customer's site is "Oh man, I wonder what kind of run down gear they are running this on"....

In no way am I bashing PFSense, it's a wonderfull product made by very competent people, but at the end of the day, I'd rather be backed by either Cisco TAC, or Dell Support should something go wrong with the device and I need to have it RMAed out. This and many other reasons, stability, etc.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Can you still click his nose in the about box?
    • In that case this product has no value to me. I'd rather use older Creative SB that were better in my opinion or onboard audio chip.
    • FxSound 1.2.9.0 / 1.2.10.0 Beta by Razvan Serea FxSound (formerly DFX Audio Enhancer / FxSound Enhancer) is now free, making high-quality audio enhancement accessible to everyone. Designed for all PC sound systems, from average setups to audiophile-grade equipment, it offers automatic or fully customizable processing. As automatic or customizable as you want, it utilizes the highest-grade processing to deliver more volume, better equalization, and a wider, deeper sound. For the serious audiophiles, FxSound gives you the tools to adjust the FxSound Effects and EQ to your exact preferences. Turn FxSound on and immediately hear the difference in sound quality. FxSound is ideal for budget audiophiles, music lovers, gamers, transcriptionists, Netflix enthusiasts, and more. It’s particularly beneficial for those relying on quiet laptop speakers or low-quality audio hardware. As a free tool, FxSound excels in boosting volume, enhancing bass, and improving sound quality. No other free EQ for Windows matches its ease of use. FxSound Is Now Completely Free and Unrestricted FxSound Pro is now free for everyone, not just those who can afford it. Get free and unrestricted access to better sound today. FxSound is now entirely supported by users. Click here to donate to help fund continued development and improvements to FxSound. FxSound 1.2.9.0 changelog: Auto save preset when Equalizer or Effects settings are changed Reset to factory defaults can reset the unsaved preset changes Settings dialog UI improvements for Audio and Equalizer sections Output device list is now displayed in the device preference order Preset is selected immediately when the preset for an active output device changes from settings Fixes and improvements in preferred output device selection Fixed crash issue #487 Fixed preset not getting applied and EQ flat after update (#403 and #472) Fixed system audio device not being restored on reboot (#483) Fixed preset export and import dialogs not shown when always on top is enabled Fixed audio not being restored on exit after the preset save dialog Fixed FxSound on/off handling on Windows session changes FxSound 1.2.10.0 Beta changelog: Command line options can now be applied to an already running instance of FxSound Command line option added to launch FxSound minimized to the system tray Fixed output device not being changed through hotkeys when FxSound is off (#524) Individual hotkeys can now be disabled with Delete key (#515) Fixed the but to prevent invalid hotkeys from being registered (#523) Bluetooth devices removed from device settings are removed from device preference list Fixed device detection failures Fixed application hang when retrieving the audio mix format fails Fixed presets import dialog file name combo box text alignment Fixed output device not being applied through command line Fixed a delay blocking application load when minimizing to the system tray Fixed EQ band sliders not refreshing when switching number of bands (#521) Fixed user-set mute being overridden by FxSound Fixed icon visibility in ARM64 version Finnish language support added Corrected Persian translations Download: FxSound 1.2.9.0 | ARM64 | ~70.0 MB (Open Source) Download: FxSound 1.2.10.0 Beta | ARM64 View: FxSound Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • mIRC 7.84 Final by Razvan Serea mIRC is a full featured Internet Relay Chat client for Windows that can be used to communicate, share, play or work with others on IRC networks around the world, either in multi-user group conferences or in one-to-one private discussions. It has a clean, practical interface that is highly configurable and supports features such as buddy lists, file transfers, multi-server connections, SSL encryption, proxy support, UTF-8 display, customizable sounds, spoken messages, tray notifications, message logging, and more. mIRC also has a powerful scripting language that can be used both to automate mIRC and to create applications that perform a wide range of functions from network communications to playing games. mIRC has been in development for over a decade and is constantly being improved and updated with new technologies. mIRC 7.84 changelog: Added custom dialog editbox option 'optional' for grayed out optional text. Fixed DirectShow temporary wave file not being deleted on exit. Changed $urlget() to retry a connection without compression in the event of an error. Updated code signing certificate to use Azure Artifact Signing. Fixed menubar display bug when in dark mode. Fixed /server -a not preserving existing entry's codepage. Fixed Address Book nick colors "idle time" display bug. Changed installer to no longer require administrator access on startup. Added support for displaying an MDI window's System menu when right-clicking its titlebar. Updated libararies to OpenSSL v3.5.7, TagLib v2.2.1, Zlib v1.3.2, and ADA v0.5.5. Updated CA root certificates cacert.pem file. For a full list of recent changes, please see the versions.txt file. Download: mIRC 7.84 | 4.3 MB (Shareware) View: mIRC Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      470
    2. 2
      +Edouard
      165
    3. 3
      PsYcHoKiLLa
      107
    4. 4
      Michael Scrip
      87
    5. 5
      Steven P.
      70
  • Tell a friend

    Love Neowin? Tell a friend!