Firewall – Are there other application layer firewalls like Microsoft TMG (ISA) that do advanced http rules

firewallhttpisa-servermicrosoft-ftmg-2010reverse-proxy

Since the old days, ISA and now TMG have had several great features that I often want to deploy to my customers because of the enhanced functionality and security, but often the cost of an additinal server HW, Windows Server, and TMG license is too much to justify when compared to a $300-500 appliance.

Are there other gateway firewalls that can perform one or more of these application layer features:

  1. Pre-authenticate incoming HTTP traffic against AD/LDAP before sending packets to internal server (forms auth or basic creds popup)?
  2. Read host headers of incoming HTTP traffic (even on https) to a public IP and route packets to different internal servers based on that host header?

Best Answer

True application/proxy firewalls in appliance form generally run above that range. (Palo Alto and Sidewinder... I mean McAfee Firewall Enterprise come to mind, but are $$).

I would recommend the FortiNet FortiGate 60C. It is a really solid box, and a no-frills system would cover your two requirements at around $500.

  • HTTP/HTTPS preauthentication support using LDAP auth source
  • HTTP/1.1 Host header based load balancing - Should allow the routing you described
Related Topic