Changes

Jump to: navigation, search

Comparison

1,844 bytes added, 14:36, 10 April 2016
no edit summary
This is a '''biased''' comparison page, that highlights the strengths of the ''security router''. We don't revise this page very often, and the information might be out of date. Please contact us, if you find any errors.
 
{| class="wikitable"
! !! Halon securityrouter 3.0-p17 7 !! pfSense 2.0.1 !! m0n0wall 1.33 !! Vyatta 6.4 <ref>Bought by Brocade, terminated open source edition, forked</ref> !! Mikrotik 5.20!! Smoothwall 3.0sp3
|-
| Cost || Free/paid || Free || Free || Free/paid || Paid || Free/paid|- | Platform || OpenBSD 5.0 9 || FreeBSD 8.1 3 || FreeBSD 6.4 || Linux 3|| Linux 2.0.23 6 || Linux 2.6|-| Firewall || PF || Forked PF<ref>pfSense uses a modified version of FreeBSD's PF, forked from OpenBSD 4.1's PF (but improved and updated in some areas)</ref> || ipfilter || iptables || iptables || iptables|-| Architecture || Intel 32/64-bit || Intel 32/64-bit || Intel 32-bit || Intel 32-bit || Intel 32-bit || Intel 32/64-bit|-! Management !! !! !! !! !! !!|-| Config format || [[Configuration_file|Clear-text]] || XML || XML || Clear-text || Semi-clear-text || Binary (floppy)|-| Restore/rollback without reboot || [[Backend|Yes]] || No || No || No || No || No|-| Test/confirm without reboot || Yes || No || No || No || No || No
|-
| Firewall Revision-managed config || PF Yes (2011Subversion) || PF Yes (2007files) || No || ipfilter Yes (file rotation) || iptables No || iptablesNo
|-
| Architecture Commit multiple changes || Intel 32/64-bit Yes || Intel 32/64-bit No || No || Intel 32-bit Yes || Intel 32-bit No || Intel 32-bitNo
|-
! Management !! !! !! !! !!| CLI config editor || [[Configure|Yes]] || No || No || Yes || Yes || No
|-
| Config format API || Clear-text [[SOAP]] || XML No || XML No || Clear-text REST || Custom || Semi-clear-textNo
|-
| Restore/rollback without reboot || Yes || No || No || No || No! VPN and encapsulation !! !! !! !! !! !!
|-
| Test/confirm without reboot VXLAN || Yes || No || No || No || No || No
|-
| Revision-managed config L2TP || Yes (SVN) || Yes (files) || No || Yes|| Yes || No
|-
| Commit multiple changes PPTP NAT passthrough || [[Proxies#PPTP_proxy| Yes ]] || No <ref>The package Frickin is sometimes mentioned, but it supposedly doesn't work in latest version</ref> || No || Yes (iptables) || Yes (iptables) || No
|-
| CLI config editor DNS suffix in PPTP/L2TP || [[VPN_server#Search_domain| Yes ]] || No || No || No || Yes No || YesNo
|-
! VPN server !! !! !! !! !!| Client routes in PPTP/L2TP || [[VPN_server#Routing|Yes]] || No || No || No || No || No
|-
| L2TP Filter-ID for RADIUS || [[VPN_server#Groups| Yes ]] || No || Yes No || No || Yes|| YesNo
|-
| PPTP NAT passthrough || Yes || ? (Fricking) || No || Yes (iptables) || Yes (iptables)! Routing !! !! !! !! !! !!
|-
| DNS suffix in PPTP/L2TP MPLS || Yes (PE/VPN) || No || No || No || Yes || No
|-
| Filter-ID for RADIUS OSPF/BGP || [[BGP| Yes ]] || Package<ref>OpenBGPD and friends are available as a package</ref> || No || No Yes (Quagga) || No Yes || ?No
|-
! Routing !! !! !! !! !! | BGP TCP-MD5 || Yes || No<ref>Last time we checked, it could be configured manually with <tt>setkey</tt>, but inbound TCP-MD5 was not verified</ref> || No || Yes || Yes || No
|-
| MPLS || Yes (PE/VPN) || No || No || No || Yes! IPv6 !! !! !! !! !! !!
|-
| BuiltFirewall rules || [[IPv6|Dual-in OSPF/BGP stack]] || Yes (OpenBGP/OSPFD) Rule duplication || No Rule duplication || No Rule duplication || Yes (Quagga) Rule duplication || YesNo
|-
! | Layer-3 translation (eg. NAT64) || [[IPv6 !! !! !! !! !!|Yes]] || No || No || No || No || No
|-
| Firewall rules || [[IPv6|Dual-stack]] || Separate ruleset || Separate ruleset || ? || ?! Others !! !! !! !! !! !!
|-
! Others !! !! !! !! !!| SIP proxy || Yes || Package<ref>The siproxd package is available, but it typically requires a bit of configuration as the traffic from the phones needs to be directed to the proxy</ref> || No || Yes || Yes || Yes
|-
| Layer 7 load balancing VMware image || Yes (OVA) || No <ref>Discontinued and is no longer offered for pfSense 2.1 and later</ref> || No || Yes || No|| ?No<ref>Found no VMware release of latest version (3.0sp3)</ref>
|-
| Re-arrange graphs Layer 7 load balancing || [[Load balancing| Yes ]] || No || No || No || ? || ?No
|}
 
<references />

Navigation menu