Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: Re: pix vs. ios firewall feature set

Re: pix vs. ios firewall feature set

From: Duncan Sharp <drsharp_at_pacbell.net>
Date: Tue, 03 Jun 2003 09:43:45 -0700

"Noonan, Wesley" wrote:

> Just curious, but why not throw a PIX 501 or 506 in the small offices?
> Obviously, needing something other than an Ethernet interface requires a
> router, but in my experience a lot of small offices are hanging off of DSL,
> Cable Modem or Ethernet wired BANs (building area networks) so a PIX (or any
> of the other SOHO firewalls) works really good.
>

Hi;

    aDSL has the special case that there are two possible router/fw solutions
    based on CISCO hardware:

        1: The 1417 router with IOS fw feature set. But this has device has
been
            is EOL, and the last IOS version is 12.1 .
            These have gone for about $150-$250 on eBay.

        2: The 1720 with wic-ADSL. This is a more current product from CISCO.
            FW feature set is possible as is IDS features.
            Last combo on eBay went for $700.

    Both options eliminate any SP modem[bridge]/router. One device to track
    up/down and error rate on DSL link. The wic-adsl is also useable with
    2600/3600/3700 routers and possibly 1600 series.

    Of course not all aDSL services are the same, you need to verify that
either
    option works with your provider.

Yours,
Duncan Sharp

>
> Wes Noonan, MCSE/CCNA/CCDA/NNCSS/Security+
> Senior QA Rep.
> BMC Software, Inc.
> (713) 918-2412
> wnoonan_at_bmc.com
> http://www.bmc.com
>
> > -----Original Message-----
> > From: Paul Stewart [mailto:pauls_at_nexicom.net]
> > Sent: Monday, June 02, 2003 07:21
> > To: avraham_at_jct.ac.il; firewall-wizards_at_icsalabs.com
> > Subject: RE: [fw-wiz] pix vs. ios firewall feature set
> >
> > I posed this question previously and was told that almost all features at
> > incorporated into the IOS. The features I use most are in both but I'm
> > sure
> > there's features that are not in the IOS FW Feature Set.. Kinda wish
> > someone
> > had a list of what's *not* in the IOS... Anyone? :)
> >
> > My adoption of using IOS for firewalling has been that of for small
> > clients
> > (under 100 workstations).... Anything over 100 or so users I use a PIX box
> > specifically....
> >
> > Take care,
> >
> > Paul
> >
> >
> > -----Original Message-----
> > From: firewall-wizards-admin_at_honor.icsalabs.com
> > [mailto:firewall-wizards-admin_at_honor.icsalabs.com] On Behalf Of avraham
> > shir-el (arthur sherman)
> > Sent: Saturday, May 31, 2003 5:33 PM
> > To: firewall-wizards_at_icsalabs.com
> > Subject: [fw-wiz] pix vs. ios firewall feature set
> >
> >
> >
> > gentlemen:
> > a cisco engineer recently told me that the plan for the above 2 products
> > is
> > %100 feature convergence and that currently, there's about %80 of the
> > features of pix present in the ios firewall feature set. any comments as
> > to
> > the reality of the above?
> >
> > tnx
> > ams
> > avraham shir-el
> > director of computing center
> > jerusalem college of technology - machon lev
> > p. 972-2-675-1163 _______________________________________________
> > firewall-wizards mailing list firewall-wizards_at_honor.icsalabs.com
> > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
> >
> > _______________________________________________
> > firewall-wizards mailing list
> > firewall-wizards_at_honor.icsalabs.com
> > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards_at_honor.icsalabs.com
> http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Received on Jun 04 2003

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]