Firewall – Why Buy High-End Hardware Firewalls?

ciscofirewalljuniperlinux

There exist firewalls from Juniper and Cisco that cost more than a house.

So I wonder: what does one get from a $10.000+ firewall compared to an 2U server with 4x 10Gbit network cards running e.g. OpenBSD/FreeBSD/Linux?

The hardware firewalls probably have a web interface.

But what else does one get for a $10.000 or $100.000 firewall???

Best Answer

It's just a matter of scale. The thousands-of-dollars firewalls have features & capacity allowing them to scale & be managed globally. A myriad of features that anyone not using them would have quite a bit of research to do before they (we) could appreciate their individual merits.

Your typical home router doesn't really need to be able to handle an officeful of devices or multiple ISP connections, so it's cheaper. Both in the number/type of interfaces, and the hardware capacity (RAM, etc). The office firewall also may need some QoS, and you might want it to be able to make a VPN connection to a remote office. You'll want slightly better logging for that small office than you'd need for the home firewall, as well.

Keep scaling that up until you need to handle a few hundred or thousand users/devices per site, connect to dozens/hundreds of other firewalls the company has globally, and manage it all with a small team in one location.

(I forgot to mention IOS updates, support contracts, hardware warranties - and there are probably a few dozen other considerations that I don't even know about...but you get the idea)

Related Topic