Recommended Posts

^ yeah its hard to beat pfsense for "cost" FREE, you just need to provide some hardware to run it on and some setup time.

It will run on pretty much anything, you have a old pc around? There you go - your hardware.

  • Like 2

Any Cisco ISR will do this. But honestly you should be looking for a combined device with a NIPS, Malware filtering go incoming downloads aswell as the bog standard stateful firewall.

As always its the rules that matter and unless its set to implicit deny its worthless.

A issue also with pFsense is that other people in the office mostly know how to control it....With most common routers, this is possible With pFsense you have to take 10 minutes.

If you don't give them the admin password they will not be able to control it.

  • Like 2

dude I have been trying to help him in the other thread he has started.. If your not talking a 150 router its going to be over budget. Reread what he posted - he wants the other others to be able to control it.

He has no concern with content filtering, talk of SNORT - you might as well be talking talking nuclear physics to a 3 year old.

His clients ask his 10 year old zyxel for dns, and they are members of domain - I would bet this is 99% of his issues. The router his looking for is something you would pick up at your computer store for $20, not a SMB/Enterprise class firewall.

"A issue also with pFsense is that other people in the office mostly know how to control it....With most common routers, this is possible With pFsense you have to take 10 minutes."

I don't get it. It's a problem when people know how to control it? It takes a whopping 10 min to look at the GUI to figure it out? To me, it sounds like he doesn't want them to be able to figure it out and it is a problem if they can.

I don't think english is his native language.. screen shots of machines are in spanish I believe.

Notice the "With pFsense you have to take 10 minutes." - and in his other thread he clearly states that he looked at pfsense but it was too complicated ;)

"A way better firewall; pFsense seems complicated so Im thinking Cisco or DD-WRT."

So I take it he wants the office to be able to understand the router, not the other way around.

pFSense.. it is free.. I am sure you have some old hardware you can put it on.. I am not sure why you would want the whole office to use it..? They'll just have that crap shredded to pieces.. Sonicwalls are ok for the money.. you get what you pay for in that aspect.. If you are dead set against doing what most of everyone here is recommending.. look into getting a nice Cisco Router and loading DD-WRT

Let's be real for a second. Unless you're doing Site to Site VPNs, or need a remote access VPN for mobile users, then you might want to consider keeping a simple router setup. You really aren't going to find a "real" firewall that Joe Enduser can understand and operate. NAT, PAT, and VPN cryptography isn't something even the normal "admin" understands. This is just a pill that has to be swallowed. They might be able to set up users or something for remote access, but everything else should probably be left alone. If they don't then who do you think they will end up calling for help?

That being said. If a true firewall solution is what's needed, then if you have the knowledge (and believe me it takes a good bit) then a Cisco ASA 5505 is going to be about the best you can get for a very small office or a spoke site. If the learning curve is to great, then go with SonicWall gear, as others have mentioned. Either way you go, make sure that (as with all technology implemented in a production/business environment) you get a support contract, to get updates/assistance etc.

Don't waste time on unsupported freeware products. Not only is this very unwise, but you'll find yourself tearing all of them out if a merger ever happens because they aren't "standard" gear that most companies use.

Let's be real for a second. Unless you're doing Site to Site VPNs, or need a remote access VPN for mobile users, then you might want to consider keeping a simple router setup. You really aren't going to find a "real" firewall that Joe Enduser can understand and operate. NAT, PAT, and VPN cryptography isn't something even the normal "admin" understands. This is just a pill that has to be swallowed. They might be able to set up users or something for remote access, but everything else should probably be left alone. If they don't then who do you think they will end up calling for help?

That being said. If a true firewall solution is what's needed, then if you have the knowledge (and believe me it takes a good bit) then a Cisco ASA 5505 is going to be about the best you can get for a very small office or a spoke site. If the learning curve is to great, then go with SonicWall gear, as others have mentioned. Either way you go, make sure that (as with all technology implemented in a production/business environment) you get a support contract, to get updates/assistance etc.

Don't waste time on unsupported freeware products. Not only is this very unwise, but you'll find yourself tearing all of them out if a merger ever happens because they aren't "standard" gear that most companies use.

I don't see how you think PFSense, Smoothwall, Monowall, Untangle, etc, aren't REAL firewalls? I agree they aren't at the same level of an ASA, but there is nothing wrong with them. I know a LOT of businesses that use PFSense. For one thing, to get any support with the ASA (including downloads for upgraded firmware), then that will be more money.

For that matter, most of those firewalls have support options available, either through them or someone else. You also don't need a support contract. Just pay when you need it from one of those companies or vendors.

If you can't figure out PFSense, or any other firewall, an ASA isn't going to be any easier.

I don't see how you think PFSense, Smoothwall, Monowall, Untangle, etc, aren't REAL firewalls? I agree they aren't at the same level of an ASA, but there is nothing wrong with them. I know a LOT of businesses that use PFSense. For one thing, to get any support with the ASA (including downloads for upgraded firmware), then that will be more money.

For that matter, most of those firewalls have support options available, either through them or someone else. You also don't need a support contract. Just pay when you need it from one of those companies or vendors.

If you can't figure out PFSense, or any other firewall, an ASA isn't going to be any easier.

I didn't say that the ASA was the most "simple" solution, nor the most cost effective. I agree that it's quite the opposite. Just saying that amongst most large enterprises it's what I see the most of. If you have the knowledge, you can get a 5505 going for < $1000.

If I couldn't go the ASA route, then I wouldn't hesitate going SonicWall simply because of the quality support and also due to the fact that most enterprise level engineers are familiar with them.

If someone calls me in the middle of the night for a support call, and I have to tunnel into some homebrew PFSense box, then the first thing that pops in my head before I VPN to the customer's site is "Oh man, I wonder what kind of run down gear they are running this on"....

In no way am I bashing PFSense, it's a wonderfull product made by very competent people, but at the end of the day, I'd rather be backed by either Cisco TAC, or Dell Support should something go wrong with the device and I need to have it RMAed out. This and many other reasons, stability, etc.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Google reportedly set to lose two key Gemini and DeepMind researchers to Anthropic by Karthik Mudaliar Google is reportedly preparing to lose two more prominent artificial intelligence researchers, with Gemini contributors Jonas Adler and Alexander Pritzel planning to join rival AI developer Anthropic. According to a report from Bloomberg, both researchers are viewed internally as important contributors to Google’s flagship Gemini model family. Adler worked on Google’s AI coding efforts, while Pritzel was involved in the process used to train AI systems. Neither company has publicly confirmed the moves. The report also does not say when the researchers will formally leave Google or what positions they will hold at Anthropic. Training a large AI model requires decisions covering its architecture, data preparation, distributed computing infrastructure, and post-training methods that shape how the finished system behaves. Researchers with experience operating at the scale of Gemini are consequently difficult to replace quickly. Both Adler and Pritzel have previously contributed to Google DeepMind’s scientific research as well. They are listed among the authors of the company’s work on expanding AlphaFold protein-structure predictions across entire proteomes, alongside AlphaFold researchers including John Jumper. The reported departures arrive shortly after another important change within Google’s Gemini organization. Gemini co-lead Noam Shazeer is leaving Google for OpenAI, after returning to the search company in 2024 through its deal with Character.AI. Shazeer is particularly well known as one of the authors of the Transformer paper, whose architecture became the foundation for most modern large language models. Anthropic, meanwhile, has been recruiting recognizable figures from other leading laboratories. OpenAI co-founder and former Tesla AI director Andrej Karpathy joined Anthropic’s pre-training team in May. His move, followed by the reported recruitment of several Google researchers, suggests Anthropic is strengthening the research teams responsible for the core capabilities of future Claude models rather than concentrating solely on product and enterprise sales. The competition is complicated by the companies’ extensive commercial relationships. Anthropic competes directly with Google’s Gemini models, but it also relies on Google as an infrastructure partner. In April, Anthropic announced an expanded agreement with Google and Broadcom covering multiple gigawatts of next-generation Tensor Processing Unit capacity. TPUs are Google-designed accelerators used to train and run large AI models. via Bloomberg
    • Google adds built-in computer control to Gemini 3.5 flash by Karthik Mudaliar Google has added Computer Use as a built-in tool in Gemini 3.5 Flash, giving developers a single model that can reason about a task and operate graphical interfaces across browsers, mobile devices, and desktop environments. The feature is available through the Gemini API and Google’s Gemini Enterprise Agent Platform, although it remains a preview feature for now. Computer Use enables an AI agent to examine screenshots and return actions such as mouse clicks, scrolling, and keyboard input. A developer’s application must execute those actions, capture the resulting screen, and send it back to Gemini, creating a continuous loop until the task is completed. Google says the integration can be used for activities including repetitive form filling, application testing, research across multiple websites, and longer enterprise workflows. Gemini 3.5 Flash can work with browser, mobile, and desktop environments, whereas Google’s earlier standalone Computer Use model was primarily positioned around browser interaction. The main change is consolidation. Computer control was previously offered through the separate Gemini 2.5 Computer Use preview model. As Neowin reported when that model was introduced, it was designed to interpret a visual interface and generate actions without requiring a website-specific API. Google later brought Computer Use to preview versions of Gemini 3 Pro and Gemini 3 Flash in January 2026. The latest release now incorporates the tool into the stable Gemini 3.5 Flash model rather than requiring developers to select a specialized model solely for interface automation. Gemini 3.5 Flash itself was announced in May as Google’s latest fast model for coding and multi-step agent workflows. It supports a one-million-token input context window and up to 65,000 output tokens, along with adjustable thinking levels that let developers trade additional reasoning for lower latency and cost. Google also added that Gemini 3.5 Flash received targeted adversarial training for computer-use scenarios. The company is also offering safeguards that can require user confirmation before sensitive or irreversible actions and automatically stop a workflow when suspected prompt injection is detected. Its developer documentation describes configurable protections for areas such as financial transactions and changes to sensitive records. Google isn't the first to bring Computer Use to its platform. Anthropic has made computer control available through Claude, while OpenAI has continued improving computer-use performance in its recent models. Microsoft has also applied the concept to business workflows, including a Computer Use capability for the Researcher agent in Microsoft 365 Copilot.
    • After I installed KB5095093, the volume on my ARM laptop won't go above 20%. It's stuck on the hearing protection level, which is pretty much useless if you want to listen to anything. I rolled back.
    • Amazon Prime Day slashes Samsung's newest Galaxy Watch Ultra by 45 percent by Karthik Mudaliar Samsung’s flagship Android smartwatch has received one of its steepest Prime Day cuts. Amazon has dropped the 2025 Samsung Galaxy Watch Ultra in Titanium Blue to $357.24, saving buyers around $292 from its $649.99 list price. That's a 45 percent discount (purchase link below). The 47mm Galaxy Watch Ultra uses a titanium casing and a 1.5-inch Super AMOLED display with a resolution of 480 x 480 and peak brightness of 3,000 nits. It includes LTE connectivity, Bluetooth 5.3, Wi-Fi, NFC, and dual-frequency L1+L5 GPS for more accurate outdoor route tracking. The 2025 model has 64GB of storage, a 590mAh battery, sapphire crystal glass, 10ATM water resistance, IP68 protection, and MIL-STD-810H durability testing. Its health and fitness tools include heart rate monitoring, sleep coaching, Energy Score, Running Coach, body composition analysis, temperature sensing, and ECG support, where available. This model is best suited to Android users who regularly run, hike, cycle, or train outdoors and want cellular access without carrying a phone. The larger battery, rugged construction, bright display, and dedicated Quick Button also make it a stronger option than Samsung’s regular Galaxy Watch models for extended workouts and demanding environments. Grab the Titanium Blue Galaxy Watch Ultra before the Prime Day price resets: Samsung Galaxy Watch Ultra (2025) [Sold and Shipped by Amazon] Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
  • Recent Achievements

    • Dedicated
      Scoobystu earned a badge
      Dedicated
    • First Post
      Tom Schmidt earned a badge
      First Post
    • One Month Later
      D0nn13 earned a badge
      One Month Later
    • Rookie
      +ChiefOfNeo went up a rank
      Rookie
    • One Year In
      Tom Schmidt earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      463
    2. 2
      +Edouard
      177
    3. 3
      PsYcHoKiLLa
      124
    4. 4
      Michael Scrip
      80
    5. 5
      Xenon
      76
  • Tell a friend

    Love Neowin? Tell a friend!