Skip to content
Notifications
Clear all

what firewall actually works for a 5-eng team on a tight budget?

2 Posts
2 Users
0 Reactions
0 Views
(@ericd)
Reputable Member
Joined: 2 weeks ago
Posts: 247
Topic starter   [#22372]

We've all been there. The team is growing, the budget isn't, and the old firewall is either a licensing nightmare or a performance bottleneck. You need something that doesn't collapse under policy complexity, has decent logging you can actually search, and won't require a dedicated full-time engineer to manage.

For a team of five, I'm assuming you need solid security, role-based administration, and maybe some VPN capacity for remote engineers, all without breaking the bank. The "tight budget" part is tricky, because it often means upfront cost *and* ongoing TCO.

I've been testing an SRX300 series box in our lab for a similar use-case. The hardware is surprisingly affordable, but the real win is Junos. The CLI is consistent and scriptable, which is a huge plus if anyone on the team has a networking background. You can segment config access cleanly, and the logging is sent to the local RE, which you can then forward to a syslog server. For a small team, avoiding a separate log server or manager license early on is a genuine cost saving.

The catch, as always, is the advanced security features (like UTM, AppID) which require a license subscription. You can run a solid stateful firewall and IPSec VPN without it, but you need to be honest about your needs. Have any of you run an SRX in a similar scenario? I'm particularly curious about real-world throughput once you have a few hundred policies and some site-to-site tunnels active. Also, how painful was the initial setup without a paid support contract?

Let's share some concrete numbers if possible—actual throughput achieved, NFR discount experiences, or even config snippets for team access control. The goal here is to figure out if this platform can truly be a "set it and forget it" workhorse for a small, busy team.

— Eric


Keep it civil, keep it real.


   
Quote
(@devops_dad_joke)
Estimable Member
Joined: 5 months ago
Posts: 122
 

You lost me at the subscription license for the advanced features. That's where Juniper gets you - and that's where your TCO math can fall apart if you need more than basic L4 rules down the line.

For a tiny team, have you considered just running OPNsense on a cheap Protectli appliance? The hardware cost is low, you get all the features (including solid VPN with WireGuard) without a subscription, and the web UI is something a developer can actually understand. It's not as "enterprisey," but for five people, you probably don't need that complexity anyway.



   
ReplyQuote