Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Software VS appliance licensing/performance difference have a few questions

I am evaluating  UTM 9.3 as a TMG replacement. At the moment have been using the software version of UTM 9.3 running as a Hyper-V virtual machine running on a Clustered  set of 2012R2 Hyper-V hosts  (Dell PowerEdge servers). Looking at the licensing models for full guard licensing seems like the appliance based  version does not have user limits whereas the software based seems to be based on the amount of users (what is considered a user as far as the licensing is concerned, the home version is based on a 50 IP connection so are we talking  method of what they are counting as a user).

What is the simplest route to exporting  all our TMG (enterprise ) rules to the UTM 9.3. Its one thing to just setup a trial /testing version and setting up the rules from scratch but not something I would look forward to on a production level.

We have been running several Forefront TM enterprise servers  in arrays that are virtualized. Though for many years Isa/TMG  were not recommended to be run virtualized for security  reasons but that was later rescinded and since Forefront TMG  we have been running them virtualized and for the most part has been easier to manage and support than on physical dedicated servers. Any thoughts on  appliance VS software when it comes to UTM 9.3?   The  answer to my first question might make the decision for us  when it comes to cost constraints in the licensing scheme. Software would be the preferred  as it gives more flexibility  but not if it is going to cost a fortune  if we have to base it on our user numbers



This thread was automatically locked due to age.
Parents
  • "what is considered a user as far as the licensing is concerned" Users is IPs. IPv4 and IPv6 are counted separately if you're using dual stack.

    "What is the simplest route to exporting all our TMG (enterprise ) rules to the UTM 9.3." There isn't a migration tool, so you'd need to recreate your configuration manually.

    "Any thoughts on appliance VS software when it comes to UTM 9.3?" Traditionally, one of the main advantages of going with software has been the ability to upgrade hardware without needing to buy a new appliance. This is less the case with the SG line of appliances, as they are more generous with RAM and CPU than the old UTM or ASG line were. It is possible to get an unlimited user license for software, but it is not a standard SKU, so you're reseller will need to hammer out a deal with Sophos sales.

    Your next step would be to discuss with a reseller your needs, so they can provide pricing options.
    __________________
    ACE v8/SCA v9.3

    ...still have a v5 install disk in a box somewhere.

    http://xkcd.com
    http://www.tedgoff.com/mb
    http://www.projectcartoon.com/cartoon/1
  • thank you Scott,

    So from my understanding physical appliances have no user limit but rather limited on what the hardware can handle based on built in RAM and CPU where as software appliance is limited based on number of users (IPs)
    The reason I asked about unlimited is the complication of properly determining the number of users which I am assuming means the number of IPs that are going to go through / filtered by the UTM. So I am thinking an inventory of how many IPs we have in use currently would be what we should base our sizing rather than our user base since we have quite a few devices not user based but would be passing through the UTM firewall service
Reply
  • thank you Scott,

    So from my understanding physical appliances have no user limit but rather limited on what the hardware can handle based on built in RAM and CPU where as software appliance is limited based on number of users (IPs)
    The reason I asked about unlimited is the complication of properly determining the number of users which I am assuming means the number of IPs that are going to go through / filtered by the UTM. So I am thinking an inventory of how many IPs we have in use currently would be what we should base our sizing rather than our user base since we have quite a few devices not user based but would be passing through the UTM firewall service
Children
No Data