Khan, > We are in process of creating policy on how much (if > any)control can we give to department's administrators > to the firewall that will be installed at demarc > point. (snips) > Have a look at smoothwall GPL, right out of the box it blocks anything above :1024, and has 2 zones. 3 nics, install in old PC, you're ready to rumble. I wouldn't give 'em any privvies, but then you can remote admin the thing over SSL from your desk, in the event they had some oddity needing higher ports. 20 meg download, you can have it running in about 30 minutes. If the free GPL version won't do it, they offer a commercial version, although 0 experience with it here - cheers, /b
--------------------------------------------------------------------------- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! The Gartner Group just put Neoteris in the top of its Magic Quadrant, while InStat has confirmed Neoteris as the leader in marketshare. Find out why, and see how you can get plug-n-play secure remote access in about an hour, with no client, server changes, or ongoing maintenance. Visit us at: http://www.neoteris.com/promos/sf-6-9.htm ----------------------------------------------------------------------------