Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-Disclosure] PIX vs CheckPoint |
|---|---|
| Date: | Tue, 29 Jun 2004 16:16:16 -0400 |
On Tue, 2004-06-29 at 13:24 -0500, Darkslaker wrote:
i am studying for the CCSA and my Friend for CSPFA in the interchange of ideas we did not find differences significant; maybe two ; PIX run in OS for CISCO and CheckPoint in many platforms; and checkPoit have more products. My question is PIX or Checkpoint what is better and why.
"Better" would really be relative here. I've used both quite a bit and my personal preference is for PIX. The reasons being: 1) Cost, 2) Simplicity, 3) reliability. Checkpoint throws more stuff in the box, but you may never use a large portion of that stuff. I've also found that each version of Checkpoint (and we aren't talking major version like 1.0 vs 2.0, but 4.1 FP3 vs 4.1 FP4) seems to introduce all kinds of new quirks and quibbles that make things quite a pain to deal with. I've never used the PIX gui for anything, I understand recent versions are better, but I prefer command line myself. The Checkpoint GUI is ok, nothing to write home about, but it is quite functional. VPN setup with Checkpoint is quite easy (especially if you tried to do IPSEC in other arenas). Failover with PIX is tremendously simpler and Just Works (tm) compared with Checkpoint. I much prefer the straight text config which I can keep in a CVS repo and do diffs on the configs over periods of time to see what has changed. Has proven useful in employee termination scenarios as well. In the end, both are viable solutions for a firewall. If you already have an investment in Checkpoint stuff, it is the obvious choice. If you are a big Cisco shop, PIX will fit in quite easily (it's OS isn't IOS, but it's not really that far off). If you do go with Checkpoint, do the world a favor and don't run it on a Windows box. Run it on Linux or Solaris or buy a Nokia IPxxx to run it on. -- David T Hollis <dhollis@davehollis.com>
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-Disclosure] SSH vs. TLS, Gerhard den Hollander |
|---|---|
| Next by Date: | RE: [Full-Disclosure] PIX vs CheckPoint, Otero, Hernan (EDS) |
| Previous by Thread: | [Full-Disclosure] PIX vs CheckPoint, Darkslaker |
| Next by Thread: | Re: [Full-Disclosure] PIX vs CheckPoint, Laurent LEVIER |
| Indexes: | [Date] [Thread] [Top] [All Lists] |