RE: [fw-wiz] Hunt for VPN devices

From: R. DuFresne (dufresneat_private)
Date: Mon Oct 14 2002 - 17:58:20 PDT

  • Next message: James Maher: "Re: [fw-wiz] Proverbial appliance vs software based firewall"

    Useful links to this thread might well be <watch for wrapping>:
    
    http://www.icsalabs.com/html/communities/ipsec/certification/certified_products/index.shtml
    
    Tina Bird's site has moved;
    
    http://vpn.shmoo.com/
    
    
    Thanks,
    
    Ron DuFresne
    
    On Mon, 14 Oct 2002, Scot Hartman wrote:
    
    > Jeff,
    > 
    > I'm on the same hunt but not seeing any dedicated appliances left.
    > We currently use several Nokia CryptoClusters as dedicated appliances
    > but they are end-of-life.  I remember when we first started using
    > them, there were several niche appliances available.  Most have
    > closed shop.
    > 
    > However, the prices on some of the firewall/vpn appliances have 
    > come down enough to where you could just use them for your VPN. 
    > And they have some FW functionality to greater or lesser degree
    > if needed.
    > 
    > There are probably 10 appliance options out there with respectable 
    > IPSec performance (so they claim, still need to put them in a lab) 
    > for fairly inexpensive ($500 - $1000).
    > 
    > I've got a list of the ones I've dug up, with their claimed numbers
    > and prices if you want me to send them to you.
    > 
    > 
    > Scot
    > 
    > 
    > 
    > -----Original Message-----
    > From: Jeff Boles [mailto:bolesjbat_private]
    > Sent: Monday, October 14, 2002 2:00 PM
    > To: firewall-wizardsat_private
    > Subject: [fw-wiz] Hunt for VPN devices
    > 
    > 
    > Hate to ask this question here, but I'm a bit stumped - are there any
    > dedicated VPN devices left on the market?
    > 
    > I used to love the redcreek dedicated vpn devices (before they were acquired
    > by SonicWall).
    > 
    > These days, seems that all VPN services are either on a firewall or router
    > box, and I favor architectures which don't really use VPN on either.  Still
    > stuck on the idea of being able to run and manage VPN separately, and
    > grouping this functionality on a firewall or router device muddies the
    > administration for clients, and adds unnecessary functionality, especially
    > for clients with restricted technical resources.  Additionally, I don't
    > really like compromising on VPN functionality or firewall functionality, and
    > multipurpose boxes seem to require either that, or an excessively high cost.
    > 
    > Thanks for any suggestions,
    > 
    > JB.
    > 
    > _______________________________________________
    > firewall-wizards mailing list
    > firewall-wizardsat_private
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    > _______________________________________________
    > firewall-wizards mailing list
    > firewall-wizardsat_private
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    > 
    
    -- 
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            admin & senior security consultant:  sysinfo.com
                            http://sysinfo.com
    
    "Cutting the space budget really restores my faith in humanity.  It
    eliminates dreams, goals, and ideals and lets us get straight to the
    business of hate, debauchery, and self-annihilation."
                    -- Johnny Hart
    
    testing, only testing, and damn good at it too!
    
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizardsat_private
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    



    This archive was generated by hypermail 2b30 : Mon Oct 14 2002 - 18:11:35 PDT