Firewall-1

Re: [FW-1] Checkpoint vs. Cisco ASA

Subject: Re: [FW-1] Checkpoint vs. Cisco ASA
From: cisco4ng <cisco4ng AT YAHOO DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Wed, 22 Nov 2006 10:49:45 -0800
Sin,
  It is ok for you to drink the cisco Kool Aid but please do not make 
statements without
  knowing exactly what the requirements might be.  Cisco Pix/ASA performs much
  better than Checkpoint BUT there are limitations to what it can and can not 
do.
  The 7.x code is so unstable that it is not funny.  That's why you see the 
letter 7.x.x(ED)
  for Early Deployment (aka beta) on the 7.x code.  Problem is that ASA 
appliances run
  only on 7.x code with Pix firewall can run on 6.3(5) code which is GD 
(General Deployment).
   
  Jeremy,
  Unless you have specific reasons to go with Cisco Pix/ASA, I would recommend 
that you
  stay with Checkpoint.  I am NOT a checkpoint fan (I bash checkpoint on a 
regular basis
  in term of the TAC support) but I have to give credit where it is due.  In 
term of 
  firewall management, Checkpoint is the best in the class.  Try to deploy a 
policy with
  20 physical/logical interaces with about 800 rules on the Pix/ASA device and 
you will see
  what I mean.
   
  Now if you want to migrate from checkpoint to ASA/Pix due to better TAC 
support from
  Cisco, then I would say "go for it".  Otherwise, stay with Checkpoint.
   
  cisco4ng

sin <sin AT IMACANDI DOT NET> wrote:
  Sean Donaghey/HDGH wrote:
> Hi,
> 
> Our company is considering replacing our Checkpoint firewall for a Cisco 
> ASA-5520 appliance. Does anyone on this list have any experience with ASA 
> box, and if so what is your opinion on them. We are currently running 
> R55 on our Corrent SR200 appliance, and are looking at migrating to a Dell 
> Poweredge 1950 server with R61/R62 (not sure which is best to go to).
> 
> I need some ammunition on pros/cons of Cisco compared to Checkpoint.
> 
> Any information would greatly be appreciated.
> 

the price/performance of ASA is unbeatable by FW-1 (i mean for about
8000usd you get an appliance that has no silly users limit, enough
troughput for a medium company, and supports addons like ids, vpn
accelerator at a fraction of the cost).
if you like a pretty gui for managing the firewall, cisco isn't that great.

i would go for cisco without a second thought.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================


 
---------------------------------
Sponsored Link

Mortgage rates as low as 4.625% - $150,000 loan for $579 a month. Intro-*Terms

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>