We are in the planning stages right now, going to invest in full suite of Sophos products. We currently have 8 pfSense boxes with site-to-site Static Key OpenVPN Tunnels deployed on SuperMicro hardware, they are working great, but we need to comply with NIST 800-171, basically requiring a fully integrated security platform, unfortunately.
- We have 3 main sites where file, AD and application servers are located.
- Each of these sites will have XG Firewall installed on existing SuperMicro C2758 hardware (8-Core, 8GB Memory, Quad Intel NIC). Although I don't think we can afford the XG license to utilize all 8 cores. Will likely end up getting the 2-core, 4GB RAM FullGuard license.
- The remaining 5 sites are home offices with 1 person each, they all have dedicated broadband business connections, 100x20 mbps minimum.
- It would be nice to utilize the existing superMicro appliances at these 5 sites its relatively new/powerful hardware I'd hate to scrap.
Question 1) Is there a licensing option that would allow for SD-RED functionality only, and not the full suite of XG features?
- If not, I assume we have to purchase SD-RED 20 appliances. Looks like they are about $350, I highly doubt there will be licensing option that costs less then this. So, a few questions about those appliances.
Question 2) Does the SD-RED 20 allow for multiple simultaneous tunnels? For example, home office site #1 SD-RED 20 appliance can connect to each of the 3 main sites where the XG Firewalls are located. This would allow for more direct routing rather then always having to traverse 1 site.
Question 3) Does the SD-RED 20 require a router be installed before it, or does it have the ability to specify/pull an IP from the ISP? At the home sites, we currently have Cable Modem -- Router. Could we replace that Router with the SD-RED 20, or would it have to be: Cable Modem -- Router -- SD-RED 20, where the LAN port of the Router connects to the WAN port of the SD-RED 20, essentially double NAT'ing?
thanks!
This thread was automatically locked due to age.