Open source firewall alternatives
Bruce Potter · Network Security · 2006
Most enterprises look no further than the major commercial vendors when it comes to planning future firewalls. But open source firewalls – often poo-pooed as overly simplistic – can now be used in a much wider range of situations and are better suited for complex and demanding environments. Traditional firewalls have provided security and network engineers real enterprise functionality: high throughput, stateful filtering, ease of management, automatic failover, and highly reliable operation. For larger enterprises, these the cost of these firewalls are easily outweighed by their benefits. But for many the price may be burdensome or the feature set may simply be more than is needed. But due to the work of large numbers of developers, the open source firewall alternatives have become serious competitors to their commercial brethren. Open source firewalls still may not be for everyone, but they are certainly beginning to make a difference. When most enterprises start examining options for firewalls, they instinctively consider the major commercial firewall vendors. Product offerings such as Cisco's Pix, Checkpoint's Firewall-1, and FortiNet's FortiGate all bubble to the surface. These firewalls have historically provided security and network engineers real enterprise functionality: high throughput, stateful filtering, ease of management, automatic failover, and highly reliable operation. For larger enterprises, these the cost of these firewalls are easily outweighed by their benefits. However, for many the price may be burdensome or the feature set may simply be more than is needed.