• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

VPN firewall recommendation

DarkOne_BW

Limp Gawd
Joined
Apr 21, 2002
Messages
472
First let me say that I've been using the Cisco RVS4000 (v2) across 60-ish locations. I've seen 3 that were lemons right OTB, and another 7 that exhibit configuration instability no matter the firmware they run.

I'm looking for a recommendation for an alternative small VPN firewall with the following features:

IPSec VPN (OpenVPN is not an option, already have established VPN running through ASA at home-office)
At least 4 VLANs
Able to assign different subnets to each VLAN
able to provide DHCP on each VLAN
ACL support
easy to stage multiple units (easily modified config files ala Cisco IOS)

I would use an ASA5505, but in order to support more than 3 VLANs I end up going WAY over budget. Each remote office has between 3 and 7 desktops, so thruput isn't nearly as important as stability. I'd like to stay under $400.

The RVS042 almost completely matches my needs, except the VLAN/DHCP support is terrible; I can't subnet VLANs or have DHCP work independently on the individual networks.

I'm looking for real-world experience with these devices please. Thanks!
 
Can I ask why you need 4 vlans with only 3-7 desktops? Does each site have a large DMZ server farm or something?

The low end Sonicwalls, Junipers and Cisco ASA's fit that bill, except for the cost.
 
firewall_recommendation.jpg


VLAN 1 functions as a remote-office extension through the VPN
VLAN 200 will be touched by the public and cannot be trusted to access the VPN. VLAN200 will also have a whitelist ACL that only allows access to a few websites.
VLAN 500 is open WiFi access, unrestricted by ACL.

VLANs 200 and 500 need DHCP running in their respective subnets.

The mutiple VLAN support is due to physical exposure of desktops (public vs corporate facing) and the need to secure the connectivity with a single Internet conection into the remote office.

Also, while the base ASA 5505 supports "3 VLANs" one of those is consumed by the outside interface, so you really only have 2 VLANs to work with on the 5505.
 
For what it's worth, I can do all this with the RVS4000 but those devices are exceptionally flaky so I need a replacement.
 
A pfSense install on an ALIX board will fit all those needs, but I've never done a software upgrade on one remotely with vlan support enabled. That would be my only worry.

You might want to relax one of your requirements (cost?) unless somebody else has a suggestion. I agree that something easy to configure and upgrade remotely is of vital importance, so that leaves dd-wrt out.

If speed isn't important, you might also get away with a low end Cisco router if you are an IOS junkie, like a 1700 series.
 
Low end fortiwifi box. I have no personal experience with anything smaller than an 80C but the smaller units have the same feature set and can hit hit your price target.
 
The ISO install based pfSense is rock-solid with VLANs IMO and experience. Software upgrade with VLANs has been smooth as butter.
 
I've had decent luck with the low end Zyxel USG stuff for Branch offices. Something like a USG 50 should fit your bill.
 
Thanks for the recomendation. I've got a Zyxel USG-50 inbound from NewEgg. Here's hoping it does everything I need and more!
 
Thanks for the recomendation. I've got a Zyxel USG-50 inbound from NewEgg. Here's hoping it does everything I need and more!

If you have questions, call Zyxel support. Do not bother e-mailing them.

The phone support is good, the e-mail support is questionable.
 
Low end fortiwifi box. I have no personal experience with anything smaller than an 80C but the smaller units have the same feature set and can hit hit your price target.

I work for a company that deploys fortigates with the wifi option built in and we have seen some issues with the firewalls running really high cpu utilization and causing the firewall to start acting up. We've been working with Fortinet engineers on the issue so they say they have fixes in the works.

The 3040B that we have at the site I work at has 0 issues but is only running UTM and firewall, no wifi.

just food for thought.
 
I just setup a Site-to-Site VPN with 2 RV180Ws and they seem pretty nice so far, setup a guest VLAN with DHCP on either one and haven't had any issues but I didn't set up any advanced ACLs and this is only one VPN connection. (they support up to 10 I believe).
 
Back
Top