Educause Security Discussion mailing list archives

Re: Next Generation Firewalls


From: Robert Lau <Robert.Lau () USC EDU>
Date: Fri, 19 Jun 2015 19:42:18 +0000

I rarely see actual pricing in these discussions, so I asked our Fortinet reps for numbers I could share. Note that 
.edu pricing is usually much lower but I cannot share those publicly.



Most of our internal core firewalls are Fortinet 1500D's (50-80Gbps aggregate throughput). ~$46k each.

We are replacing some with Fortinet 3700D's (110-160Gbps). ~$154k each.

Our border firewall will soon be a Fortinet 3810D (already racked but waiting for a firmware update). ~$387k. But most 
people do not need a 4x100Gbps firewall.



All are "NGFW" which I also think is a silly marketing term, because what is after "next"? Next^2 Generation Firewall? 
Like LifeLock's Ultimate Plus. How can you plus-ify Ultimate? But I digress.



Based on how much traffic we pump through them, I think the 1500D's have enough capacity (IPS throughput, new sessions 
per second, etc) for all internal and external traffic at a medium-sized school, especially if you have more than one 
in an all-active cluster.



-robert



-----Original Message-----

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Swick, 
Forrest

Sent: Thursday, June 18, 2015 10:17

To: SECURITY () LISTSERV EDUCAUSE EDU

Subject: Re: [SECURITY] Next Generation Firewalls



Seems like many places are in refresh mode . . .



Here's a blog I came across when we were in the search. . .



https://blog.anitian.com/utm-v-ngfw-a-single-shade-of-gray/



There are many fans of many different vendors and their technologies . . .



Here's how we voiced our recommendations after looking at many vendors.



NGFW = UTM

NGFW $ > 200,000

UTM $ < 200,000

For the Enterprise . . . you get the same features . . . just can pay more if you want.



We all have read the Gartner Quadrant reviews and NSS Labs reports . . .



Enjoy the Search and Replacment!



--Forrest



Forrest H. Swick, CISSP

IT Security Analyst

Office of Information Security

Information Management & Technology





University of Northern Colorado

Carter Hall 3008B

501 20th Street

Campus Box 19

Greeley, CO 80639



O: 970-351-1379

C: 970-397-1343

F: 970-351-1650

unco.edu



Once a Bear, Always a Bear!



UNC Technical Support? Please dial 970.351.4357 / 800.545.2331 To receive online assistance visit http://help.unco.edu



-----Original Message-----

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Tornoe, 
Eric J.

Sent: Thursday, June 18, 2015 11:01 AM

To: SECURITY () LISTSERV EDUCAUSE EDU

Subject: Re: [SECURITY] Next Generation Firewalls



We also replaced our Cisco ASA's with an Active/Passive pair of Palo Alto NGFW in January 2015 and are very happy with 
our choice. I agree with Andrea that the increase in visibility and protection right out of the box is impressive. Ease 
of management was  a big deal to us since we have limited staff and the Palo has delivered on that aspect. Palo Alto 
was great to work with and we have an ongoing relationship with our sales engineer that has been extremely fruitful 
even following the sale. We considered Cisco, CheckPoint and PA before choosing the PA on cost, effectiveness and ease 
of management.



Eric





Eric J. Tornoe

Enterprise Architect and Manager, Security and Database Operations Information Resources and Technologies University of 
St. Thomas

2115 Summit Avenue

St. Paul, Minnesota 55105

Mail Location: 5046 Office: AQU LL13G

Phone: 651.962.6217







-----Original Message-----

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Di 
Fabio, Andrea

Sent: Thursday, June 18, 2015 11:30 AM

To: SECURITY () LISTSERV EDUCAUSE EDU

Subject: Re: [SECURITY] Next Generation Firewalls



Hi Tim,



We migrated from a pair of CISCO ASA's 5540 to an Active/Passive pair of PaloAlto NGFW 3 years ago and we couldn't be 
happier with features, performance, and ease of management. We are managing the pair without the management server, 
Panorama. They have increased our security posture and network visibility by a great deal. Our bake-off was, PA vs 
CISCO vs Barracuda vs SonicWall.



Andrea Di Fabio

Interim Chief Information Officer (CIO)

Office of Information Technology

Marie V. McDemmond Center for Applied Research, Rm 401H

555 Park Avenue, Suite 401

Norfolk, Virginia 23504

(757) 823-2896 (Office)

(757) 823-2128 (Fax)

adifabio () nsu edu

www.nsu.edu



________________________________________

From: The EDUCAUSE Security Constituent Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of Carroll, Tim 
<Carrolltd () ROANESTATE EDU>

Sent: Thursday, June 18, 2015 10:00

To: SECURITY () LISTSERV EDUCAUSE EDU

Subject: [SECURITY] Next Generation Firewalls



All,



Roane State Community College is in the process of reviewing next generation firewalls.  Since this is a significant 
investment, I would be interested in hearing from the community what you are using, your experience, why you made the 
choice and your satisfaction with the vendor chosen.



Thanks in advance for any feedback.



Regards,



Tim Carroll

Assistant Vice President and Chief Information Officer Information Technology Roane State Community College



________________________________



This email is intended for the addressee and may contain privileged information. If you are not the addressee, you are 
not permitted to use or copy this email or its attachments nor may you disclose the same to any third party. If this 
has been sent to you in error, please delete the email and notify us by replying to this email immediately.

Current thread: