NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW-1] [Fwd: Re: [FW-1] comparison between Pix and FW-1]



-------- Original Message --------
Subject: Re: [FW-1] comparison between Pix and FW-1
Date: Wed, 31 Oct 2001 16:59:45 -0500
From: Steven Wu <[email protected]>
To: Mailing list for discussion of Firewall-1
<[email protected]>
References: <[email protected]>

Just my 2 cents:

It totally depends on what way you look at it. If cost is not an issue,
I
would stick with Checkpoint at this time, especially you already have a
CP
FW-1. Checkpoint does provide a lot of features within its fw-1
software. I
think as being a network admin, checkpoint log does a better job than
most
of the firewalls(netscreen, watchguard ...)and PIX is still using the
syslog
level, not easy to maintain and not secure enough.

For the obvious comparison I can think of :

PIX over Checkpoint:

1. Cost. PIX is a lot cheaper.
2. Document. Cisco provide much much better documentation web site and
great
tech support than no one can beat at this market.

CP over PIX :
1. Log maintnance.
2. Nice Gui for policy editor and various security server features for
content filtering. Easy for security admin trouble shoot.
3. Load Balance cluster feature.

I think most people right now use Nokia with CP HA solution to cut down
the
cost. There is another hardware platform you might need to pay attention
to
is Netscreen products. Personally, I think Netscreen is doing the right
direction : low cost and also combine both PIX and Checkpoint FW-1
advantages together with a nice Web configuration GUI and log
maintanance.

Good luck,

Steven


John Castillo wrote:

> can anyone highlight the differences, advantage/disadvantage of each FW
> solution?
>
> my boss is looking into replacing FW-1 with a Pix in a datacenter
> environment.  no one has done much research except for the common
> argument that "the pix is a hardware accelerated firewall, therefore its
> better and faster".
>
> opinions?
>
> ===============================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> ===============================================

===============================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
===============================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.