Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Four reasons to buy (and one reason to avoid) the Droid
Cisco MARS shuts out new third-party security devices
Verizon Droid buzz muted in Boston
Week in Google news: Google Dashboard, Droid fever, focus on e-commerce
Cloud computing, virtualization proponents getting antsy
Data center start-up offers energy saving software
Vendors scrambling to fix bug in Net's security
Judge dismisses lawsuit challenging Gartner's Magic Quadrant
Boston Celtics clamp down on spam
Cloud computing inevitable? Not so fast, educator says
Blue Coat slashes staff, buys S7 services company
Apple seeks new sheriff to lock up iPhones
Google releases new search engine for e-commerce sites
Rackspace apologizes for cloud outage, prepares to issue service credits
/

Reviews /

Firewalls RFP

Today's breaking news
Send to a friendFeedback

Editor's Note: The following sample firewalls RFP was prepared by The Tolly Group to help users prepare for purchasing firewalls. You can see vendor responses by clicking on their names on the right.

Happy Pharmaceuticals, Inc. has a three site enterprise network that is connected to the Internet at multiple points. Currently the company is not using firewalls, but instead has a few older proxy servers that are limited in scalability and functionality. The company's business has been growing so it is upgrading its current dual T1 connections from the central site network to higher bandwidth T3 connections. The two regional sites will be upgraded from fractional T1 connections to the Internet to full T1 connections.

Current and Future Firewall Requirements

Happy Pharmaceuticals requires its network to be highly available, achieving at least a 99.99% uptime; otherwise known as 'four nines' availability. Any firewall technology put in place must be able to maintain 'four nines' availability, at a minimum. Having a backup firewall on 'hot' standby, ready to take over from the primary firewall is a viable option, if it is not cost prohibitive. The current planned connection to the Internet from the Central Site is over dual T3 connections. The T3's go to separate ISPs and will both be used for traffic. (see figure 1)

The firewall solution chosen must be able to process high speed traffic since a switched Fast Ethernet connection is on one side of the firewall (100 Mbit/s) and a 45 Mbit/s T3 connection is on the Internet side. The majority of the traffic will be FTP and HTTP traffic and more than 3000 user sessions are possible at any given time. Since the company has developed some of their own applications for use over the Internet, the firewall should provide some capability to customize security features to address new or unknown applications. The firewall should be able to handle up to 3000 user sessions and still provide additional room for growth.

Since Happy Pharmaceuticals' network is growing, the network managers want to run Network Address Translation (NAT) on the firewall to allow them to use a larger IP address space. The Firewall solution should not negatively affect the network performance even with NAT running.

Centralized management of all the firewalls, central site as well as remote site, is critical since there is limited resource available on the IT team and travel between sites is very costly. Each firewall's rule base should be stored and updated in one single location and distributed securely to each firewall as needed. Figure 1 shows the proposed location of the firewalls throughout the upgraded network.

A strong security logging capability and log file analysis with report generation is also required. This capability can be built into the firewall or a separate workstation on the network. It could be a 3rd party product that interfaces with the firewall completely. If an attempted attack or break in occurs and is logged, the firewall should have some mechanism to page a network manager or alert the standard network management platform.

Happy Pharmaceuticals is expecting to receive a plan that describes the number of firewalls required to meet the above requirements and the recommended configuration of the firewalls. A total cost for the solution is also required as well as the cost of any 3rd party software that the vendor recommends for log file analysis.

Diagram 1. Happy Pharmaceuticals Proposed Future Network

Vendor responses:
  • Axent
  • BorderWare
  • Check Point
  • Cisco
  • CyberGuard
  • Elron
  • LanOptics
  • Livermore
  • Lucent
  • NetScreen
  • Radguard
  • Sun
  • RELATED LINKS

    The responses
    See how 12 vendors responded to this RFP.

    Review: Firewalls
    Raptor Firewall 6.0 takes top honors in our testing. Network World, 7/19/99.

    Issues and trends
    Where the firewall market is headed and what to look for. Network World, 7/19/99.

    Interactive buyer's guide
    Detailed specs on 52 models. Find the one that meets your criteria or compare two or more models on different specs.

    Forum: Firewalls
    Post your firewalls questions and discuss their use in this forum.

    Firewalls to the rescue
    Interviews with firewall users. Network World Fusion, 7/19/99.


    NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
    Click here to sign up!
    New Event - WANs: Optimizing Your Network Now.
    Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
    Attend FREE
    Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
    * HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

    Contact us | Terms of Service/Privacy | How to Advertise
    Reprints and links | Partnerships | Subscribe to NW
    About Network World, Inc.

    Copyright, 1994-2006 Network World, Inc. All rights reserved.