Re: SMB firewall (was RE: VLAN N00b)

2011-08-04 Thread Ben Scott
On Wed, Aug 3, 2011 at 4:42 PM, David Lum david@nwea.org wrote: So ideally in your opinion the firewall would effectively give each VLAN (each VLAN defined by 802.1Q tags) it's own DHCP scope and thus their own IP settings, correct? More or less. I would separate your desired access

RE: SMB firewall (was RE: VLAN N00b)

2011-08-04 Thread David Lum
off with this little project. Dave -Original Message- From: Ben Scott [mailto:mailvor...@gmail.com] Sent: Thursday, August 04, 2011 5:34 AM To: NT System Admin Issues Subject: Re: SMB firewall (was RE: VLAN N00b) On Wed, Aug 3, 2011 at 4:42 PM, David Lum david@nwea.org wrote: So

RE: SMB firewall (was RE: VLAN N00b)

2011-08-04 Thread David Lum
don't? Dave -Original Message- From: David Lum [mailto:david@nwea.org] Sent: Thursday, August 04, 2011 6:08 AM To: NT System Admin Issues Subject: RE: SMB firewall (was RE: VLAN N00b) Yep, what you describe is exactly what I was envisioning, thanks! (BTW Dell also calls it tagging). Now

Re: SMB firewall (was RE: VLAN N00b)

2011-08-04 Thread Harry Singh
thought you'd use but really don't? Dave -Original Message- From: David Lum [mailto:david@nwea.org] Sent: Thursday, August 04, 2011 6:08 AM To: NT System Admin Issues Subject: RE: SMB firewall (was RE: VLAN N00b) Yep, what you describe is exactly what I was envisioning, thanks

Re: SMB firewall (was RE: VLAN N00b)

2011-08-04 Thread Andrew S. Baker
but really don't? Dave -Original Message- From: David Lum [mailto:david@nwea.org] Sent: Thursday, August 04, 2011 6:08 AM To: NT System Admin Issues Subject: RE: SMB firewall (was RE: VLAN N00b) Yep, what you describe is exactly what I was envisioning, thanks! (BTW Dell also calls

RE: SMB firewall (was RE: VLAN N00b)

2011-08-04 Thread Crawford, Scott
Are you saying that av/content filtering is you least important criteria of all on a FW? Or that's it's the bottom of your must haves? From: Andrew S. Baker [mailto:asbz...@gmail.com] Sent: Thursday, August 04, 2011 12:23 PM To: NT System Admin Issues Subject: Re: SMB firewall (was RE: VLAN N00b

RE: SMB firewall (was RE: VLAN N00b)

2011-08-04 Thread Martin Blackstone
Have any of you guys checked out Palo Alto Networks? From: Crawford, Scott [mailto:crawfo...@evangel.edu] Sent: Thursday, August 04, 2011 3:18 PM To: NT System Admin Issues Subject: RE: SMB firewall (was RE: VLAN N00b) Are you saying that av/content filtering is you least important

Re: SMB firewall (was RE: VLAN N00b)

2011-08-04 Thread Kevin Lundy
, August 04, 2011 3:18 PM To: NT System Admin Issues Subject: RE: SMB firewall (was RE: VLAN N00b) Are you saying that av/content filtering is you least important criteria of all on a FW? Or that's it's the bottom of your must haves? From: Andrew S. Baker [mailto:asbz...@gmail.com] Sent

Re: SMB firewall (was RE: VLAN N00b)

2011-08-04 Thread Andrew S. Baker
of you guys checked out Palo Alto Networks? ** ** *From:* Crawford, Scott [mailto:crawfo...@evangel.edu] *Sent:* Thursday, August 04, 2011 3:18 PM *To:* NT System Admin Issues *Subject:* RE: SMB firewall (was RE: VLAN N00b) ** ** Are you saying that av/content filtering is you

Re: SMB firewall (was RE: VLAN N00b)

2011-08-04 Thread Andrew S. Baker
is going to pay off with this little project. Dave -Original Message- From: Ben Scott [mailto:mailvor...@gmail.com] Sent: Thursday, August 04, 2011 5:34 AM To: NT System Admin Issues Subject: Re: SMB firewall (was RE: VLAN N00b) On Wed, Aug 3, 2011 at 4:42 PM, David Lum david

RE: SMB firewall (was RE: VLAN N00b)

2011-08-04 Thread Crawford, Scott
gotcha From: Andrew S. Baker [mailto:asbz...@gmail.com] Sent: Thursday, August 04, 2011 6:55 PM To: NT System Admin Issues Subject: Re: SMB firewall (was RE: VLAN N00b) It's the feature that my clients tend to use/implement the least frequently on a UTM device. ASB http://about.me

RE: SMB firewall (was RE: VLAN N00b)

2011-08-04 Thread Martin Blackstone
Same here. Other than that they are awesome. -Original Message- From: Kevin Lundy [mailto:klu...@gmail.com] Sent: Thursday, August 04, 2011 4:18 PM To: NT System Admin Issues Subject: Re: SMB firewall (was RE: VLAN N00b) Yes. Have two PAs clustered. Love the security aspect

RE: SMB firewall (was RE: VLAN N00b)

2011-08-03 Thread Paul Hutchings
the documentation is on the Juniper website but as with most firewall vendors it's like 2000 pages so can be a bit heavy going. Paul From: David Lum [david@nwea.org] Sent: 03 August 2011 8:53 PM To: NT System Admin Issues Subject: SMB firewall (was RE: VLAN N00b

Re: SMB firewall (was RE: VLAN N00b)

2011-08-03 Thread Kurt Buff
Don't know, but here's what I've got running. We're using Cisco 1240AG WAPs, but I think the situation is analagous. I made sure that our firewall's internal interface had two VLANs that didn't talk with each other, but that each had access to the Internet - each VLAN interface is a different

Re: SMB firewall (was RE: VLAN N00b)

2011-08-03 Thread Ben Scott
On Wed, Aug 3, 2011 at 3:53 PM, David Lum david@nwea.org wrote: Use the Dell switch, have the firewall be promiscuous and VLAN off the various ports so they can only see the firewall as well as get DHCP from it. I would tend to prefer to keep IP traffic completely separated -- different

Re: SMB firewall (was RE: VLAN N00b)

2011-08-03 Thread Andrew S. Baker
Also look at the Fortigate 50 series... * * *ASB* *http://about.me/Andrew.S.Baker* *Harnessing the Advantages of Technology for the SMB market… * On Wed, Aug 3, 2011 at 3:53 PM, David Lum david@nwea.org wrote: Nice, looks like the SSG5 fits the bill. Looks like Watchguard XTM2 lives

Re: SMB firewall (was RE: VLAN N00b)

2011-08-03 Thread Kurt Buff
On Wed, Aug 3, 2011 at 13:20, Ben Scott mailvor...@gmail.com wrote: On Wed, Aug 3, 2011 at 3:53 PM, David Lum david@nwea.org wrote: Use the Dell switch, have the firewall be promiscuous and VLAN off the various ports so they can only see the firewall as well as get DHCP from it.  I

RE: SMB firewall (was RE: VLAN N00b)

2011-08-03 Thread David Lum
: Ben Scott [mailto:mailvor...@gmail.com] Sent: Wednesday, August 03, 2011 1:21 PM To: NT System Admin Issues Subject: Re: SMB firewall (was RE: VLAN N00b) On Wed, Aug 3, 2011 at 3:53 PM, David Lum david@nwea.org wrote: Use the Dell switch, have the firewall be promiscuous and VLAN off