8/14 Has anyone ever used any Netscreen hardware? I've been offered the
use of a Netscreen 100 on indefinite loan, and I was wondering if
it's worth the time/effort required to setup and experiment with.
Comments/Advice on ease/difficulty of setup as well as evidence
(anecdotal or otherwise) of the security record for Netscreen
equipment would be much appreciated.
\_ We evaluated Netscreens for my last (big) client. They decided
to buy them. Not a good idea. Take it if it's free--however,
if you want to do anything reasonably advanced with them, they
are close to useless. This includes inter-platform IPSEC,
debugging, whatnot. You are far better off with a *nix running
IPFilter for anything involving customization. Netscreens have
a cute web gui, and that's about it. As below, if the price is
right, take it--but for these, free is the only right price. -John
\_ Which devices have you been trying to interoperate them with?
-mlee
\_ I played with two Netscreen 5 (set up a home-to-office VPN last wk)
Not sure about the 100. Worth it to play with it, esp. if its free.
Everything is browser-based now. Piece of cake.
As for security, reliability and performance, I am still testing.
\_ as a former Netscreen "consultant" and reseller... they are GREAT
for simple stuff... crazy easy to configure and manage... but when
it comes down to flexibility and ease of doing some crazy stuff with
the security policy and address translation they SUCK ASS. when it
comes to VPN... they suck ass and suck some more.. Netscreens
are cheap and simple. use them for simple/small environ.. -shac
\_ If you're talking about the messy UI configuration of VPNs,
they have remedied in ScreenOS 4.0. -mlee
\_ I used an NS100 in an office. Worked fine there. Put the mail
server in dmz, the rest in the 'trusted' zone (as if I trusted any
of the stupid bastards at that company) and the internet is the
untrusted zone. Does all the basics really easily. Free is a
good price for it. Keep it.
\_ On the same token, anyone have opinions on Checkpoint FW-1 vs.
a Cisco Pix?
\_ Pix is very similar to other Cisco stuff as far as configuring
it. If you know Cisco routers, you know Cisco pix.
\_ Cisco Pix shouldn't even be in this discussion. -mlee |