Good day gurus,<\/p>\n
I need some real life advice on upgrading or replacing all my Sonicwalls, I have been a faithful Sonicwall users for years, but I think the time has come to move away from the lack of support and some basic features.<\/p>\n
Currently I have about 11 (all interconnected using VPN) units between main offices and remote location ranging in users between 8-50 and endpoints between 16-100. I am running tz-200 (lowest) and nsa-250m (highest).<\/p>\n
I find the Sonicwall’s have a good job protecting my infrastructure considering I have never been hit with a virus, or hacking, or ransomware, they are easy to configure, but I feel they lack a lot when it comes to monitoring features including traffic, user activity, blocking, as well as handling VoIP, I also find them a bit slow when all the services are activated.<\/p>\n
I have been talking to my vendor and he is recommending Fortinet, WatchGuard, Sophos, and I have personally considered pfSence.<\/p>\n
Some of the features I would like to have are GW antivirus, IDS, IPS, Botnet, Geo protection, users control, application control, the ability to control what users can do on the web including by group. GOOD monitoring, reporting and alerting.<\/p>\n
Of course budget is a big issue.<\/p>\n
Any advice is greatly appreciated.<\/p>\n
Rudy<\/p>","upvoteCount":6,"answerCount":13,"datePublished":"2019-04-25T03:08:07.000Z","author":{"@type":"Person","name":"RudyM","url":"https://community.spiceworks.com/u/RudyM"},"suggestedAnswer":[{"@type":"Answer","text":"
Good day gurus,<\/p>\n
I need some real life advice on upgrading or replacing all my Sonicwalls, I have been a faithful Sonicwall users for years, but I think the time has come to move away from the lack of support and some basic features.<\/p>\n
Currently I have about 11 (all interconnected using VPN) units between main offices and remote location ranging in users between 8-50 and endpoints between 16-100. I am running tz-200 (lowest) and nsa-250m (highest).<\/p>\n
I find the Sonicwall’s have a good job protecting my infrastructure considering I have never been hit with a virus, or hacking, or ransomware, they are easy to configure, but I feel they lack a lot when it comes to monitoring features including traffic, user activity, blocking, as well as handling VoIP, I also find them a bit slow when all the services are activated.<\/p>\n
I have been talking to my vendor and he is recommending Fortinet, WatchGuard, Sophos, and I have personally considered pfSence.<\/p>\n
Some of the features I would like to have are GW antivirus, IDS, IPS, Botnet, Geo protection, users control, application control, the ability to control what users can do on the web including by group. GOOD monitoring, reporting and alerting.<\/p>\n
Of course budget is a big issue.<\/p>\n
Any advice is greatly appreciated.<\/p>\n
Rudy<\/p>","upvoteCount":6,"datePublished":"2019-04-25T03:08:07.000Z","url":"https://community.spiceworks.com/t/utm-firewall-replacement/709005/1","author":{"@type":"Person","name":"RudyM","url":"https://community.spiceworks.com/u/RudyM"}},{"@type":"Answer","text":"
So since budget is a big issue, what would be the price per unit you would be looking to allocate? For small to medium sized businesses, Fortinet is a good choice I’ve heard although I haven’t used them and pfsense is also a really good choice considering cost and features available. Palo Alto makes a really solid box but is probably (maybe PA-220 or higher depending on your requirements) to expensive. I generally deal with Cisco but the newer models have issues with software when it comes to FirePower I’ve heard and this NGFW will probably be out of range anyway.<\/p>","upvoteCount":0,"datePublished":"2019-04-25T03:19:59.000Z","url":"https://community.spiceworks.com/t/utm-firewall-replacement/709005/2","author":{"@type":"Person","name":"anthony4190","url":"https://community.spiceworks.com/u/anthony4190"}},{"@type":"Answer","text":"
Just looking at your demands in combination with performance and budget… I don’t believe anyone can beat the WatchGuard offering in this area.<\/p>\n
The point is, that WatchGuard comes WITH their log&report server Dimension at no additional cost. Any other vendor will charge you for advanced logging and reporting.<\/p>\n
Also they will offer you a TradeIn price, that comes close to renewing the maintenance and security services on a Sonicwall for a 3year term.<\/p>\n
Management is a bit different, but still using a logic, that is close enough to SonicWall’s, so it’s not completely a different approach you have to adopt.<\/p>\n
pfSense may be the cheapest solution on your list, but when you complain about features on the SonicWall side, than it’s even worse on the pfSense side, where quite a few of the security services you are using on a commercial solution are not available or are of far lower quality. Would you want to upgrade them with come commercial grade subscriptions, than you would soon end up with a far higher price as with a commercial UTM bundle.<\/p>\n
Check it out on your own. Install, configure, see what each solution can offer you. Than do the math, how much it will really cost you.<\/p>","upvoteCount":1,"datePublished":"2019-04-25T04:27:33.000Z","url":"https://community.spiceworks.com/t/utm-firewall-replacement/709005/3","author":{"@type":"Person","name":"bojanzajc6669","url":"https://community.spiceworks.com/u/bojanzajc6669"}},{"@type":"Answer","text":"
If its visibility and monitoring you want, Sophos is the way. Fortinets are solid but lack the out of box functionality of monitoring which requires a subscription based Forti Analyzer add-on.<\/p>\n
Another Sophos advantage, for small remote sites, you can use a RED device which doesn’t require any individual licencing (one off CapEx cost) can operate in a split or tunnel mode to control remote traffic depending on the speed of the circuit, for larger sites I’d deploy a site specific UTM. Combine Endpoint Protection with Intercept X EDR & Encryption manged via Sophos Central all bases are covered<\/p>\n
I am currently a Fortinet user in a large enterprise environment but cannot knock Sophos for functionality & usability<\/p>","upvoteCount":0,"datePublished":"2019-04-25T08:14:20.000Z","url":"https://community.spiceworks.com/t/utm-firewall-replacement/709005/4","author":{"@type":"Person","name":"philmcnamara7275","url":"https://community.spiceworks.com/u/philmcnamara7275"}},{"@type":"Answer","text":"
pfSense is a good option. I’ve been using it in production for years. Build your own or snag some hardware from Netgate.<\/p>\n
It can do those things you’re looking for by adding packages from.the package manager. I’ve been using pfblocker for Geo blocking and suricata for IDS/IPS for a while.<\/p>\n
The biggest drawback is the lack of reporting you get out of the system. Otherwise, it’s rock solid.<\/p>","upvoteCount":0,"datePublished":"2019-04-25T09:13:21.000Z","url":"https://community.spiceworks.com/t/utm-firewall-replacement/709005/5","author":{"@type":"Person","name":"rebelscum","url":"https://community.spiceworks.com/u/rebelscum"}},{"@type":"Answer","text":"