This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Pros/Cons of XG Firewall? - looking for some real world experience

I am considering the XG Firewall (210 model) and would plan to implement it with high availability.  I personally come from a Cisco background and have experience with the ASA line, but I wanted to see how these models compare and what others experiences are.

Please let me know any pros/cons you have encountered and if there are any gotcha moments to be aware of.

Thanks much.

KM



This thread was automatically locked due to age.
Parents
  • We started out with the XG105 model, and even though the number should have made it work, the devices was simply too slow and came nowhere near the official specs.

    Also the throughput speeds we obtained were well below what you would expect.

    At that point in time we also had lots and lots of problems with IPS, some websites behind the firewall (we are hosting them) stopped working properly and lots of false positives as well.

    Sophos kept on saying the device was simply too slow for us. So based on this we bought a XG310, which for us was heavily overdimensioned.

    Unfortunately also this device still gives us many headaches. Again IPS is screwing things up for us. Our customers are complaining that every x 100 requests, they suddenly get a very slow reaction of the servers. We investigated this using tcpdumps on the firewall itself, and we indeed see that sometimes clients experience 6 seconds of delays.

    We tried excluding that server IP from IPS scanning, but even then the delays were happening.

    So the only choice left for us was to completely stop the IPS service, only when we did that, the box was not generating delays anymore.

    But you will also understand that defeats pretty much the purpose of having the box. 

    Currently this case is still under investigation by Sophos, so I'm hoping for the best ...

    Pros:

    Easy interface 

    Straight forward to configure in most cases

    Good visibility on what is going on in your network

     

    Cons:

    The product is not mature nor stable, it's ok for an office, but to be honest, it cant compete in ISP / corporate markets

    It's hard to reach the support, 30+ mins of holding the line before getting to a support tech are very common

     

    Hope this helps you in making whatever choice you want to make

Reply
  • We started out with the XG105 model, and even though the number should have made it work, the devices was simply too slow and came nowhere near the official specs.

    Also the throughput speeds we obtained were well below what you would expect.

    At that point in time we also had lots and lots of problems with IPS, some websites behind the firewall (we are hosting them) stopped working properly and lots of false positives as well.

    Sophos kept on saying the device was simply too slow for us. So based on this we bought a XG310, which for us was heavily overdimensioned.

    Unfortunately also this device still gives us many headaches. Again IPS is screwing things up for us. Our customers are complaining that every x 100 requests, they suddenly get a very slow reaction of the servers. We investigated this using tcpdumps on the firewall itself, and we indeed see that sometimes clients experience 6 seconds of delays.

    We tried excluding that server IP from IPS scanning, but even then the delays were happening.

    So the only choice left for us was to completely stop the IPS service, only when we did that, the box was not generating delays anymore.

    But you will also understand that defeats pretty much the purpose of having the box. 

    Currently this case is still under investigation by Sophos, so I'm hoping for the best ...

    Pros:

    Easy interface 

    Straight forward to configure in most cases

    Good visibility on what is going on in your network

     

    Cons:

    The product is not mature nor stable, it's ok for an office, but to be honest, it cant compete in ISP / corporate markets

    It's hard to reach the support, 30+ mins of holding the line before getting to a support tech are very common

     

    Hope this helps you in making whatever choice you want to make

Children
No Data