Jump to content

pfSense if you're into straight-baller status firewalls.

[FS][US] Corsair H115i 280mm AIO-AMD $60+shipping

 

 

System specs:
Asus Prime X370 Pro - Custom EKWB CPU/GPU 2x360 1x240 soft loop - Ryzen 1700X - Corsair Vengeance RGB 2x16GB - Plextor 512 NVMe + 2TB SU800 - EVGA GTX1080ti - LianLi PC11 Dynamic
 

Link to comment
https://linustechtips.com/topic/648425-good-firewalls/#findComment-8340284
Share on other sites

Link to post
Share on other sites

26 minutes ago, Mornincupofhate said:

Pfsense will shoot both of it's knee caps during a ddos attack 

meaning it's vulnerable to ddos attack? I don't catch your meaning.

 

baller ... as in basketball-er ... is superstar status.

[FS][US] Corsair H115i 280mm AIO-AMD $60+shipping

 

 

System specs:
Asus Prime X370 Pro - Custom EKWB CPU/GPU 2x360 1x240 soft loop - Ryzen 1700X - Corsair Vengeance RGB 2x16GB - Plextor 512 NVMe + 2TB SU800 - EVGA GTX1080ti - LianLi PC11 Dynamic
 

Link to comment
https://linustechtips.com/topic/648425-good-firewalls/#findComment-8345312
Share on other sites

Link to post
Share on other sites

Its the new-age lingo knightslugger.

 

Take a cue from the hard of hearing people, they just nod and smile and agree when the other people dont get the hint to speak up or speak more clearly. In this case, we both have no clue what he means by " straight-baller status" so thats what we do. Nod, Smile and Agree, then Smile and Wave. Then daydream of a tropical beach with beautiful ladies around drinking an ice cold drink.

 

Or as the great musical group Headstones song, Smile and Wave.

 

There is however the TV show Ballers starring Dwayne "The Rock" Johnson of WWF fame.

Link to comment
https://linustechtips.com/topic/648425-good-firewalls/#findComment-8345919
Share on other sites

Link to post
Share on other sites

3 hours ago, knightslugger said:

meaning it's vulnerable to ddos attack? I don't catch your meaning.

 

baller ... as in basketball-er ... is superstar status.

Meaning pfsense will absolutely die in small ddos attacks, even if they don't saturate your line. 

I had mine in a datacenter with a 1gig line, 6 cores, and 64gb of ram. The attackers send 100mbps and the thing crashed with all of my servers behind it.

Link to comment
https://linustechtips.com/topic/648425-good-firewalls/#findComment-8346531
Share on other sites

Link to post
Share on other sites

1 hour ago, Mornincupofhate said:

Meaning pfsense will absolutely die in small ddos attacks, even if they don't saturate your line. 

I had mine in a datacenter with a 1gig line, 6 cores, and 64gb of ram. The attackers send 100mbps and the thing crashed with all of my servers behind it.

This is why for any significant connection speed or enterprise use case I always recommend a hardware appliance with ASIC. Of course this isn't a one size fits all thing either though, ASIC isn't a magic bullet. You can also have a front-end firewall with ASIC to do stage 1 filtering then have a another back-end firewall to deeper inspection.

 

https://www.fortinet.com/products-services/products/fortigate/fortiasic.html

http://www.thebarriergroup.com/asic-vs-standard-processing-chips/

Link to comment
https://linustechtips.com/topic/648425-good-firewalls/#findComment-8346922
Share on other sites

Link to post
Share on other sites

13 hours ago, leadeater said:

This is why for any significant connection speed or enterprise use case I always recommend a hardware appliance with ASIC. Of course this isn't a one size fits all thing either though, ASIC isn't a magic bullet. You can also have a front-end firewall with ASIC to do stage 1 filtering then have a another back-end firewall to deeper inspection.

 

https://www.fortinet.com/products-services/products/fortigate/fortiasic.html

http://www.thebarriergroup.com/asic-vs-standard-processing-chips/

How much is a reasonable amount for one of these firewalls? Thinking about getting one.

Link to comment
https://linustechtips.com/topic/648425-good-firewalls/#findComment-8349916
Share on other sites

Link to post
Share on other sites

9 hours ago, Mornincupofhate said:

How much is a reasonable amount for one of these firewalls? Thinking about getting one.

I use a FortiGate 60D at home which is the cheapest fully (almost) featured FortiGate firewall that supports VDOMs and most SSL features. It's around $600USD for it but if you have a 1Gbps internet connection a 100D or the new 100E would be much better at around $1700USD.

 

As a warning though FortiGate firewalls need a FortiGuard subscription for the advanced UTM features to work which is an ongoing cost. A 1 year 8x5 FortiCare & FortiGuard renewal for a 100D $900USD.

Link to comment
https://linustechtips.com/topic/648425-good-firewalls/#findComment-8352483
Share on other sites

Link to post
Share on other sites

9 hours ago, Mornincupofhate said:

How much is a reasonable amount for one of these firewalls? Thinking about getting one.

I use a FortiGate 60D at home which is the cheapest fully (almost) featured FortiGate firewall that supports VDOMs and most SSL features. It's around $600USD for it but if you have a 1Gbps internet connection a 100D or the new 100E would be much better at around $1700USD.

 

As a warning though FortiGate firewalls need a FortiGuard subscription for the advanced UTM features to work which is an ongoing cost. A 1 year 8x5 FortiCare & FortiGuard renewal for a 100D $900USD.

Link to comment
https://linustechtips.com/topic/648425-good-firewalls/#findComment-8352484
Share on other sites

Link to post
Share on other sites

44 minutes ago, Canada EH said:

Pricey, but what about home pc users.

 

Is Microsoft Defender, MSE and Malwarebytes - and a cable ISP router with a current after-market wireless router enough?

Generally speaking yea. Any decent home router with their 'true firewall' and NAT, plus a reputable anti-virus software will keep you safe. I also add on to that always use an ad-blocker as extra layer of protection.

 

Most issues are user initiated where no firewall is going to help and no spam filtering is perfect or anti-virus. Best protection is awareness.

Link to comment
https://linustechtips.com/topic/648425-good-firewalls/#findComment-8353516
Share on other sites

Link to post
Share on other sites

Depending on your needs and wishes you can look into three categories:

  • Consumer grade (All the Asus, Netgear, TP-Link, etc.)
  • Pro-sumer grade (Mikrotik, Ubiquiti, etc.)
  • Pro grade (Fortinet, Cisco, Juniper, etc.)

Most home users will be very happy with consumer grade hardware. People with more advanced setups (home or small business) get pro-sumer equipment and if you're into the stuff or run a (bigger) business you need pro grade equipment and features.

 

So maybe you want something like this?... But probably, judging from your technical knowledge in your replies I think you should definitely stick with consumer grade equipment, because with each grade the ease of setup goes down (but gains in flexibility and features). The same goes for price. ;) 

 

  • Quindor from the Intermittent Technology blog (intermit.tech) and YouTube channel (Intermit.Tech)
  • Organizer of LAN-parties (1100 people) The Party and CampZone (~2000 people)
  • Officially a senior storage expert, un-officially a networking expert, besides all of that enjoys lots of different computer related subjects
  • Aspiring video maker! ;)
Link to comment
https://linustechtips.com/topic/648425-good-firewalls/#findComment-8357776
Share on other sites

Link to post
Share on other sites

Here is what I learned about which ones are good.

Paid - Bit Defender, Kaspersky

Free - Avast (Popular), Malwarebytes

Other popular - SOPHOS, Panda, Avira, Comodo.

Bit Defender and MSE

I've always been interested in ESET NOD 32 and Bit Defender, I always try to find if there are any sales on. Sometimes they sell old software for cheap. Like 2012 Panda software for $1, last version 8 of ESET NOD 32 for $10, current V9 is $30cdn.

.

I stay a mile away from anything Norton. I read they are bloated and slow.

 

Link to comment
https://linustechtips.com/topic/648425-good-firewalls/#findComment-8357806
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×