Invitation to connect on LinkedIn

2011-06-30 Thread Yaoqing Liu via LinkedIn
LinkedIn Yaoqing Liu requested to add you as a connection on LinkedIn: -- Ted, I'd like to add you to my professional network on LinkedIn. - Yaoqing Accept invitation from Yaoqing Liu http://www.linkedin.com/e/-voa23o-gpjunqoh-4g/q

Invitation to connect on LinkedIn

2011-06-30 Thread Yaoqing Liu via LinkedIn
LinkedIn Yaoqing Liu requested to add you as a connection on LinkedIn: -- Ted, I'd like to add you to my professional network on LinkedIn. - Yaoqing Accept invitation from Yaoqing Liu http://www.linkedin.com/e/-voa23o-gpjv55fb-66/q

Firewall Appliance Suggestions

2011-06-30 Thread Blake T. Pfankuch
Howdy, I am looking for something a little unique in a bit of a tough situation with some sticky requirements. First off, my requirements are a little weird and I can't bend them a whole lot due to stipulations being put on me. I am in need a firewall appliance which can be run

Re: Firewall Appliance Suggestions

2011-06-30 Thread -Hammer-
CheckPoint -Hammer- "I was a normal American nerd" -Jack Herer On 06/30/2011 10:50 AM, Blake T. Pfankuch wrote: Howdy, I am looking for something a little unique in a bit of a tough situation with some sticky requirements. First off, my requirements are a little weird and

RIP RM

2011-06-30 Thread Jay Ashworth
Robert Morris, NSA crypto maven and Unix co-developer, has died at 78 of 'complications of dementia'. Unix haters will probably say 'atojiso'; Barrett Hansen will probably be chagrined. http://j.mp/iZYd0I Cheers, -- jra -- Jay R. Ashworth Baylink j...@ba

Re: Firewall Appliance Suggestions

2011-06-30 Thread Suresh Rajagopalan
Linux + iptables + fwbuilder On Thu, Jun 30, 2011 at 8:50 AM, Blake T. Pfankuch wrote: > Howdy, >                I am looking for something a little unique in a bit of a tough > situation with some sticky requirements.  First off, my requirements are a > little weird and I can't bend them a w

RE: Firewall Appliance Suggestions

2011-06-30 Thread Blake T. Pfankuch
For those of you who responded quickly and usefully, do you have any experience with the CheckPoint/Juniper/Fortinet in an environment with multiple protected subnets running on VMware? Simple enough for a NOC monkey to make changes to without breaking assuming he has half a brain and a process

Re: Firewall Appliance Suggestions

2011-06-30 Thread -Hammer-
I do. Your NOC Monkey reference is your biggest hurdle. What you are asking for is a bit beyond "traditional" so finding something with a pretty interface for a monkey may be tough. CheckPoint will require a fat client. If that is an issue -Hammer- "I was a normal American nerd" -Jack Her

RE: Firewall Appliance Suggestions

2011-06-30 Thread Leigh Porter
I use JuNOS Juniper for just this and it works well. However, I have not used the GUI for configuring it, but the command line is very usable. However, if you have a NOC Monkey, I would be tempted to create your own front end for configuring stuff and have an XML interface to the real boxes..

RE: Firewall Appliance Suggestions

2011-06-30 Thread George Bonser
> Willing to pay for something if need be, but looking for > something that can easily handly 50-100mbit of throughput. > > Any Ideas? > > Thanks! > > Blake Pfankuch I might also look at Vyatta. They have appliances or you can run the software on your own hardware.

Re: Firewall Appliance Suggestions

2011-06-30 Thread Brent Jones
On Thu, Jun 30, 2011 at 8:50 AM, Blake T. Pfankuch wrote: > Howdy, >                I am looking for something a little unique in a bit of a tough > situation with some sticky requirements.  First off, my requirements are a > little weird and I can't bend them a whole lot due to stipulations bei

Re: Firewall Appliance Suggestions

2011-06-30 Thread Chris Lowe
- Original Message - From: Brent Jones [mailto:br...@servuhome.net] Sent: Thursday, June 30, 2011 01:46 PM To: Blake T. Pfankuch Cc: NANOG (nanog@nanog.org) Subject: Re: Firewall Appliance Suggestions On Thu, Jun 30, 2011 at 8:50 AM, Blake T. Pfankuch wrote: > Howdy, >      

Re: Firewall Appliance Suggestions

2011-06-30 Thread Rhys Rhaven
You can run pfsense in a VM, and the GUI is rather easy. VLANs are configured as separate interfaces. So once you configure which VLANs are which, your NOC monkey can simply go to the firewall and edit each VLANs separate firewall rules. The multiple Phase 2 in a single Phase 1 was added to version

RE: Firewall Appliance Suggestions

2011-06-30 Thread Blake T. Pfankuch
Normally I would agree with you as far as separate instances, however this will be in a situation where we pay ridiculous amounts for cpu and memory, so a single instance is what we are shooting for (remember those ridiculous requirements). I am planning to do some further testing with vyatta a