<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Getting out of the Hardware Appliance Racket</title>
	<link>http://blogs.isaserver.org/shinder/2006/12/01/getting-out-of-the-hardware-appliance-racket/</link>
	<description>Written by Dr Thomas W Shinder, consultant to Microsoft, HP and many Fortune 500 companies on ISA firewall and Web proxy deployments this blog is where administrators get information about ISA Server Universal Threat Management firewalls. Topics include how to manage, deploy, and troubleshoot ISA Server as a network firewall, Web proxy/Web cache, remote access VPN server and VPN gateway to provide a high level of network security for all corporate computers.</description>
	<pubDate>Thu,  4 Dec 2008 20:36:20 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: Jeff Wiltshire</title>
		<link>http://blogs.isaserver.org/shinder/2006/12/01/getting-out-of-the-hardware-appliance-racket/#comment-32833</link>
		<pubDate>Tue, 12 Dec 2006 13:26:28 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/12/01/getting-out-of-the-hardware-appliance-racket/#comment-32833</guid>
					<description>I have no idea what a Ponzi scheme is....must be a US term.  

Hardware firewalls can be purchased that will outperform ISA 2006 for less than the cost of the license fee for standard edition plus Windows 2003 license + server hardware.  There is no racket as you would like to believe.....</description>
		<content:encoded><![CDATA[<p>I have no idea what a Ponzi scheme is&#8230;.must be a US term.  </p>
<p>Hardware firewalls can be purchased that will outperform ISA 2006 for less than the cost of the license fee for standard edition plus Windows 2003 license + server hardware.  There is no racket as you would like to believe&#8230;..
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Thomas Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2006/12/01/getting-out-of-the-hardware-appliance-racket/#comment-32823</link>
		<pubDate>Tue, 12 Dec 2006 13:07:21 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/12/01/getting-out-of-the-hardware-appliance-racket/#comment-32823</guid>
					<description>The discussion isn't about the best firewall in the world, it's about how customers get duped and taken advantage of because of the &quot;hardware appliance&quot; racket. Customer waste thousands of dollars on the &quot;appliance&quot; Ponzi scheme every year.</description>
		<content:encoded><![CDATA[<p>The discussion isn&#8217;t about the best firewall in the world, it&#8217;s about how customers get duped and taken advantage of because of the &#8220;hardware appliance&#8221; racket. Customer waste thousands of dollars on the &#8220;appliance&#8221; Ponzi scheme every year.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Jeff Wiltshire</title>
		<link>http://blogs.isaserver.org/shinder/2006/12/01/getting-out-of-the-hardware-appliance-racket/#comment-32820</link>
		<pubDate>Tue, 12 Dec 2006 12:54:53 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/12/01/getting-out-of-the-hardware-appliance-racket/#comment-32820</guid>
					<description>I never said that you could provide a solution for 125,000 users for under $1000....re-read what I wrote.

Your arguement is flawed as the examples you use are not what you claim them to be and yet again you are being deliberatly disingenuous with your response.  Regardless of how you would like it to be different ISA is not the greatest firewall on the planet.</description>
		<content:encoded><![CDATA[<p>I never said that you could provide a solution for 125,000 users for under $1000&#8230;.re-read what I wrote.</p>
<p>Your arguement is flawed as the examples you use are not what you claim them to be and yet again you are being deliberatly disingenuous with your response.  Regardless of how you would like it to be different ISA is not the greatest firewall on the planet.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Thomas Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2006/12/01/getting-out-of-the-hardware-appliance-racket/#comment-32799</link>
		<pubDate>Tue, 12 Dec 2006 11:24:20 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/12/01/getting-out-of-the-hardware-appliance-racket/#comment-32799</guid>
					<description>So let me get this right -- you can provision a sonicwall or Check Point Server for 125,000 users for under a $1000? AND include IPS, DPI (marketoid speak!), AV and AS?

I'd like to see that!

BTW -- there are no flaws in the argument. Read the discussion again and you'll find all assertions irrefutable. I've proven that already because you weren't able to refute any of the assertions you called &quot;flawed&quot;.

HTH,
Tom</description>
		<content:encoded><![CDATA[<p>So let me get this right &#8212; you can provision a sonicwall or Check Point Server for 125,000 users for under a $1000? AND include IPS, DPI (marketoid speak!), AV and AS?</p>
<p>I&#8217;d like to see that!</p>
<p>BTW &#8212; there are no flaws in the argument. Read the discussion again and you&#8217;ll find all assertions irrefutable. I&#8217;ve proven that already because you weren&#8217;t able to refute any of the assertions you called &#8220;flawed&#8221;.</p>
<p>HTH,<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Jeff Wiltshire</title>
		<link>http://blogs.isaserver.org/shinder/2006/12/01/getting-out-of-the-hardware-appliance-racket/#comment-32780</link>
		<pubDate>Tue, 12 Dec 2006 10:13:19 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/12/01/getting-out-of-the-hardware-appliance-racket/#comment-32780</guid>
					<description>I occasionaly watch from afar and smile at Tom's &quot;one man crusade&quot; regarding ISA and other firewall vendors and then move on without comment.....

However this time your arguement is so flawed that it begs to be commented on.  Your choice of Hardware Appliance vendors are hardly representiative, Bluecoat don't produce hardware firewalls (they are a proxy/AV appliance company) and Cisco are hardly on the leading edge of appliance technology.  There are a large number of hardware firewall vendors making very good products which completely eclipse the capabilities of ISA 2006, I suggest you look long and hard and vendors like SonicWALL, NetASQ, Juniper, Fortienet, Nokia (with Checkpoint) etc etc.  SonicWALL have Intrusion Prevention, Deep Packet Inspection, Gateway Anti-virus, Anti-Spyware built in to a sub $1000 box.

Just in case you get the wrong idea I have built a ISA 2004 system based on 2 4-way arrays to handle 125,000 users (over 40,000 concurrent users) so I'm not a complete idiot when it comes to ISA.</description>
		<content:encoded><![CDATA[<p>I occasionaly watch from afar and smile at Tom&#8217;s &#8220;one man crusade&#8221; regarding ISA and other firewall vendors and then move on without comment&#8230;..</p>
<p>However this time your arguement is so flawed that it begs to be commented on.  Your choice of Hardware Appliance vendors are hardly representiative, Bluecoat don&#8217;t produce hardware firewalls (they are a proxy/AV appliance company) and Cisco are hardly on the leading edge of appliance technology.  There are a large number of hardware firewall vendors making very good products which completely eclipse the capabilities of ISA 2006, I suggest you look long and hard and vendors like SonicWALL, NetASQ, Juniper, Fortienet, Nokia (with Checkpoint) etc etc.  SonicWALL have Intrusion Prevention, Deep Packet Inspection, Gateway Anti-virus, Anti-Spyware built in to a sub $1000 box.</p>
<p>Just in case you get the wrong idea I have built a ISA 2004 system based on 2 4-way arrays to handle 125,000 users (over 40,000 concurrent users) so I&#8217;m not a complete idiot when it comes to ISA.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Ray</title>
		<link>http://blogs.isaserver.org/shinder/2006/12/01/getting-out-of-the-hardware-appliance-racket/#comment-30914</link>
		<pubDate>Sun, 10 Dec 2006 02:12:33 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/12/01/getting-out-of-the-hardware-appliance-racket/#comment-30914</guid>
					<description>The thing that constantly amazes me is how supposedly competent people equate &quot;hardware appliance&quot; with &quot;no maintenance required&quot; or &quot;I'm not responsible for it&quot;.

To all of you: Unless the appliance is running on mechanical relays and vacuum tubes, software is somehow involved. Software with flaws written by people just like those who write software for &quot;non-appliance&quot; firewalls.

And you are still responsible for keeping its software (a.k.a. &quot;firmware&quot;) updated and administered properly. You will lose your job for having a &quot;hardware appliance&quot; getting compromised just as fast as for a non-appliance firewall. And maybe faster if you neglect your responsibilities.

Ray</description>
		<content:encoded><![CDATA[<p>The thing that constantly amazes me is how supposedly competent people equate &#8220;hardware appliance&#8221; with &#8220;no maintenance required&#8221; or &#8220;I&#8217;m not responsible for it&#8221;.</p>
<p>To all of you: Unless the appliance is running on mechanical relays and vacuum tubes, software is somehow involved. Software with flaws written by people just like those who write software for &#8220;non-appliance&#8221; firewalls.</p>
<p>And you are still responsible for keeping its software (a.k.a. &#8220;firmware&#8221;) updated and administered properly. You will lose your job for having a &#8220;hardware appliance&#8221; getting compromised just as fast as for a non-appliance firewall. And maybe faster if you neglect your responsibilities.</p>
<p>Ray
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
