ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    SMB firewall options

    IT Discussion
    16
    57
    8.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • coliverC
      coliver
      last edited by coliver

      So... are you looking for a firewall or a UTM? If you're looking for a firewall take a look at the ER-Pro line from Ubiquiti. There are a lot of people that use them around here that love them.

      bbigfordB 1 Reply Last reply Reply Quote 7
      • brianlittlejohnB
        brianlittlejohn
        last edited by

        I like to filter by DNS. I use DYN's internet guide.

        coliverC 1 Reply Last reply Reply Quote 0
        • brianlittlejohnB
          brianlittlejohn
          last edited by

          Then have the firewall only allow outgoing DNS queries from my DNS servers.

          1 Reply Last reply Reply Quote 1
          • thwrT
            thwr
            last edited by

            Used pfSense. A bit over a decade. Never failed, expect for some broken flash drive once.

            Snort is available for pfSense.

            1 Reply Last reply Reply Quote 3
            • bbigfordB
              bbigford @coliver
              last edited by

              @coliver said in SMB firewall options:

              So... are you looking for a firewall or a UTM? If you're looking for a firewall take a look at the ER-Pro line from Ubiquiti. There are a lot of people that use them around here that love them.

              I've only ever used their WAPs and routers. I'll have to check that out.

              1 Reply Last reply Reply Quote 0
              • coliverC
                coliver @brianlittlejohn
                last edited by

                @brianlittlejohn said in SMB firewall options:

                I like to filter by DNS. I use DYN's internet guide.

                Filtering by DNS is good too. You could setup an internal proxy with something like Squid or Snort to block specific things.

                thwrT 1 Reply Last reply Reply Quote 1
                • zuphzuphZ
                  zuphzuph Banned
                  last edited by

                  Untangle. 😄

                  bbigfordB gjacobseG 2 Replies Last reply Reply Quote 2
                  • scottalanmillerS
                    scottalanmiller
                    last edited by

                    Only things I use anymore...

                    • Ubiquit for nearly everything.
                    • Sophos if they demand UTM but don't have the resources for the good stuff.
                    • Palo Alto if they really need edge security.
                    wrx7mW 1 Reply Last reply Reply Quote 4
                    • bbigfordB
                      bbigford @zuphzuph
                      last edited by

                      @zuphzuph said in SMB firewall options:

                      Untangle. 😄

                      You've gotten to mess with that more than I have. Have you checked out the content filtering and such? Does it have a VPN client? I couldn't remember if OpenVPN is available on that or if I'm thinking of pfSense...

                      thwrT scottalanmillerS zuphzuphZ 3 Replies Last reply Reply Quote 0
                      • thwrT
                        thwr @coliver
                        last edited by

                        @coliver said in SMB firewall options:

                        @brianlittlejohn said in SMB firewall options:

                        I like to filter by DNS. I use DYN's internet guide.

                        Filtering by DNS is good too. You could setup an internal proxy with something like Squid or Snort to block specific things.

                        For inbound filtering by country: https://doc.pfsense.org/index.php/Pfblocker

                        Reduces port scanning and such by a huge amount

                        1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller
                          last edited by

                          When building our own, for the lab, we use VyOS on enterprise server hardware. Basically a massive EdgeRouter.

                          1 Reply Last reply Reply Quote 3
                          • thwrT
                            thwr @bbigford
                            last edited by

                            @BBigford said in SMB firewall options:

                            @zuphzuph said in SMB firewall options:

                            Untangle. 😄

                            You've gotten to mess with that more than I have. Have you checked out the content filtering and such? Does it have a VPN client? I couldn't remember if OpenVPN is available on that or if I'm thinking of pfSense...

                            pfSense got both, client and server.

                            1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @bbigford
                              last edited by

                              @BBigford said in SMB firewall options:

                              @zuphzuph said in SMB firewall options:

                              Untangle. 😄

                              You've gotten to mess with that more than I have. Have you checked out the content filtering and such? Does it have a VPN client? I couldn't remember if OpenVPN is available on that or if I'm thinking of pfSense...

                              OpenVPN is on nearly everything.

                              bbigfordB 1 Reply Last reply Reply Quote 1
                              • bbigfordB
                                bbigford @scottalanmiller
                                last edited by

                                @scottalanmiller said in SMB firewall options:

                                @BBigford said in SMB firewall options:

                                @zuphzuph said in SMB firewall options:

                                Untangle. 😄

                                You've gotten to mess with that more than I have. Have you checked out the content filtering and such? Does it have a VPN client? I couldn't remember if OpenVPN is available on that or if I'm thinking of pfSense...

                                OpenVPN is on nearly everything.

                                Then maybe I'm thinking of both. 😄

                                scottalanmillerS 1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @bbigford
                                  last edited by

                                  @BBigford said in SMB firewall options:

                                  @scottalanmiller said in SMB firewall options:

                                  @BBigford said in SMB firewall options:

                                  @zuphzuph said in SMB firewall options:

                                  Untangle. 😄

                                  You've gotten to mess with that more than I have. Have you checked out the content filtering and such? Does it have a VPN client? I couldn't remember if OpenVPN is available on that or if I'm thinking of pfSense...

                                  OpenVPN is on nearly everything.

                                  Then maybe I'm thinking of both. 😄

                                  EdgeOS and VyOS have it too.

                                  1 Reply Last reply Reply Quote 1
                                  • JaredBuschJ
                                    JaredBusch
                                    last edited by

                                    @BBigford and FFS you still have not answer this quesiton.

                                    @coliver said in SMB firewall options:

                                    So... are you looking for a firewall or a UTM?

                                    1 Reply Last reply Reply Quote 1
                                    • JaredBuschJ
                                      JaredBusch
                                      last edited by

                                      Because your title only says firewall. but you are talking about UTM stuff in your post.

                                      bbigfordB 1 Reply Last reply Reply Quote 3
                                      • bbigfordB
                                        bbigford @JaredBusch
                                        last edited by

                                        @JaredBusch said in SMB firewall options:

                                        Because your title only says firewall. but you are talking about UTM stuff in your post.

                                        Fixed. I know it's kind of apples to oranges since one includes the other and drives up the price substantially.

                                        scottalanmillerS 2 Replies Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller @bbigford
                                          last edited by

                                          @BBigford said in SMB firewall/UTM options:

                                          @JaredBusch said in SMB firewall options:

                                          Because your title only says firewall. but you are talking about UTM stuff in your post.

                                          Fixed. I know it's kind of apples to oranges since one includes the other and drives up the price substantially.

                                          And generally we don't recommend UTMs. High cost, low results.

                                          bbigfordB 1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller @bbigford
                                            last edited by

                                            @BBigford said in SMB firewall/UTM options:

                                            @JaredBusch said in SMB firewall options:

                                            Because your title only says firewall. but you are talking about UTM stuff in your post.

                                            Fixed. I know it's kind of apples to oranges since one includes the other and drives up the price substantially.

                                            More like apples to bushels. They aren't different things, one is a big thing made up of the other.

                                            1 Reply Last reply Reply Quote 2
                                            • 1
                                            • 2
                                            • 3
                                            • 1 / 3
                                            • First post
                                              Last post