FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] Netscreen firewalls

To: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Subject: Re: [fw-wiz] Netscreen firewalls
From: Carson Gaspar <carson@taltos.org>
Date: Fri, 15 Dec 2006 16:19:54 -1000
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.icsalabs.com
In-reply-to: <000a01c72070$9531bfc0$6401a8c0@powerup64>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <1865060443.1165907094175.JavaMail.root@fepweb09> <000a01c72070$9531bfc0$6401a8c0@powerup64>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
--On Friday, December 15, 2006 12:43 PM -0500 Mike LeBlanc 
<mlinfosec@comcast.net> wrote:

> All,
> I'm looking for guidance on vulnerabilities/downsides to the Netscreen
> firewalls.  I am
> not looking to start a flamefest on Netscreen but simply am looking for
> the downside.
> We currently are a cisco pix shop and have monitoring and change
> management built
> around cisco.  I have done a google on Netscreen vulnerabilities and
> issues but
> didn't find much current data.  Any information is appreciated in advance,
> including
> links to current data.  Additionally if you have personal expereince,
> positive or
> negative, with Netscreen I would like to hear it.. off list if so desired.
>
> Thanks in advance for any information you can provide,
>
> Mike LeBlanc, CISSP
> VP/Infosec officer for multinational bank

Having done firewall evaluations for several multinational banks, NetScreen 
is pretty much the best thing out there in packet filter land. Much better 
than FW-1 and PIX, especially under heavy load. They're not perfect by any 
means, but they have the best virtual firewall support I've seen, which 
makes them great for consolidation projects or compartmentalizing your 
rules to lower operational risk. They're routing support is pretty good as 
well - if you have ethernet demarc'd WAN connections you can avoid paying 
for a separate routing tier in many cases.

-- 
Carson
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>