Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall-1 Limitations...
From: george @ neato . org
Date: Fri, 25 Jul 1997 08:20:27 -0700 (PDT)
To: martin @ nii . ncb . gov . sg
Cc: Daniel Rubin <djr @ cb-telam . com>, firewalls @ greatcircle . com, djr @ newcoast . com

Why don't you buy Sunscreen EFS from Sun instead of Firewall-1.  Faster, 
better, less restrictive licensing...

> > I thought I would post this note to the list to warn people of some
> > limitations of the Sun Soltice Firewall-1 product.  Our requirements
> > included multiple ethernet interfaces that were used to connect
> > multiple networks.  The idea was to protect one of the interfaces
> > from all the others.  The others included the internet, WAN
> > connectivity to our clients etc.  The license we purchased for
> > firewall one was the Light Security Center License since we only
> > have about 12 hosts that need to protected.
> >
> > After much research and fighting with the support reps at Sun
> > we discovered that the Light Security Center License only supports
> > one external interface (terminology used for licensing purposes).
> > As a result it counted each host it received packets from on any
> > of the other interfaces as an internal host.  That license only
> > allow 50 internal hosts.  That license was about $5000.00 and
> > it turns out the license we needed is just about $40,000.  Try to
> > sell that to management!
> 
> Someone told me FW-1 detects how many hosts you have from the broadcast
> packets of those hosts. So one way to solve your problem is to configure
> those hosts not to send out broadcast packets.
> >
> > If we knew this earlier we would have just purcased a CICSO
> > enterprise router, which does just about everything the
> > firewall-1 software does.
> 
> "Everything" ?? I am not too sure I follow you here. I think you are
> confusing FW-1 packet inspection technology with plain old packet
> filtering that ANY router is capable of doing. Anything beyond that I
> can't see for the life of me how the 2 can be comparable.

> Licensing issue aside, FW-1 is a robust and highly regarded security
> product.

Licensing not aside, Sunscreen EFS is very robust and an excellent security 
product.

- george




Indexed By Date Previous: Re: NAT
From: Pat Barry <pat @ netrex . com>
Next: Re: Chicago Network Security Specialist Position
From: Nathan Steinbauer <nathan @ datasource . net>
Indexed By Thread Previous: Test: Ignore...
From: Amin Tora <AMINT @ ICN . COM>
Next: Re: FW-1 - buy from Checkpoint or Sun?
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>

Google
 
Search Internet Search www.greatcircle.com