nuclearsnake
Limp Gawd
- Joined
- Mar 8, 2003
- Messages
- 445
Hi everyone,
I'm starting work on a new project - to remove the old linux based iptables firewalls from the office and implement a dual redundant firewall with failover. A side project is to also have some sort of web content protection and SMTP anti-spam/anti-virus in house.
I first looked into Untangle to do everything, routing, dual-wan, source based nat, firewall, anti-spam, etc, but the costs are just to high once we started adding up all the modules we were going to require to make this work.
My next idea was to use pfSense and the networking core; routing, firewall, etc, and use Untangle in bridge mode between the pfSense boxes and the rest of the networks.
The trouble I'm getting into is the following; Seeing as we have multiple subnets, how would I configure one Untangle box to do the filtering between each of the source and destination networks?
Example: WAN -> pfSense -> Untangle -> LAN is easy and simple to do, but when you also have two DMZ networks connected to the potential pfSense box, how would I tie the same Untangle box into it without needing 2NICs in Untangle for each different zone?
So far, the best thought I've had was to build two ESXi servers, each with one pfsense, one untangle, then using virtual switches to tie the untangle boxes into the networks.
I hope this made some sense...
I'm starting work on a new project - to remove the old linux based iptables firewalls from the office and implement a dual redundant firewall with failover. A side project is to also have some sort of web content protection and SMTP anti-spam/anti-virus in house.
I first looked into Untangle to do everything, routing, dual-wan, source based nat, firewall, anti-spam, etc, but the costs are just to high once we started adding up all the modules we were going to require to make this work.
My next idea was to use pfSense and the networking core; routing, firewall, etc, and use Untangle in bridge mode between the pfSense boxes and the rest of the networks.
The trouble I'm getting into is the following; Seeing as we have multiple subnets, how would I configure one Untangle box to do the filtering between each of the source and destination networks?
Example: WAN -> pfSense -> Untangle -> LAN is easy and simple to do, but when you also have two DMZ networks connected to the potential pfSense box, how would I tie the same Untangle box into it without needing 2NICs in Untangle for each different zone?
So far, the best thought I've had was to build two ESXi servers, each with one pfsense, one untangle, then using virtual switches to tie the untangle boxes into the networks.
I hope this made some sense...