WatchGuard Firebox Peak X5500e firewall
WatchGuard Firebox: Fiery performer at a nice price
- Client/server-based management system allows true offline editing of configuration, high throughput even when handling attacks, can turn on additional in-the-box features through licensing
- Blocked only a third of the attacks in our test, complex user interface, desperately needs wizards for common setup tasks (public server, VPN), must be online for initial setup, to download updates and user interface
WatchGuard Firebox Peak X5500e isn't easy to set up, but its use of XML configuration files works wonders for managing configuration across any number of devices and locations. Apart from complex initial configuration, this is a highly manageable, enterprise-grade, proxy-based firewall with impressive throughput, granular control, and an excellent price.
Price$ 5,990.00 (AUD)
When we first began working with the Firebox, we got very frustrated with all of the reboots we had to suffer through while making what we considered minor changes (IP, subnet mask, and so on). But that's because we didn't yet understand WatchGuard's client-server attitude toward configuration. Clearly enterprise in nature, the thick configuration utility wants you to check your configuration changes before you commit them. It's not a handy Web utility that could accidentally paint you into a corner. It wants you to make your changes as a single update so that individual changes can be considered before you hit the return key.
With the Firebox, you could easily have an entire lab configuration (sandbox) to do some initial testing, then pre-edit the changes necessary to drop the config into production. By the same token, you could remove a troubled unit from production and flip it into a lab setting to confirm or deny problems. WatchGuard allows you to save configuration files and swap between them really easily, regardless of whether you're touching the original serial number that the configuration was built on.
WatchGuard's client server approach started us thinking about how well the Firebox line fits regardless of your company size. From the SMB-oriented single console to a team approach with undocked windows spread across the front wall of a NOC, you could find a version of WatchGuard's hardware and combination of software that should fit your needs. This is a stratified product line with software upgrades within the hardware platform allowing you to fit the cost of the unit to your immediate needs but still permitting an easy upgrade path. From smaller Edge units to the Core SMB units all the way to the larger Peak units, the Firebox product line has granular layers allowing a much closer fit to individual company needs. The same stratification can work just as well within a highly distributed enterprise; with varying levels of authority, I could easily see firewall management becoming a team sport.
GUI or CLI?
While we were, in general, impressed by the WatchGuard, it wasn't perfect. The most significant hassle, though, came from the manufacturer's packaging rather than the basic system design; there was no software at all on the CD-ROM, nor were you able to download it from the Firebox's console. You must be able to download it from the WatchGuard site, and the first setup must be on an Internet-connected link since the system wants to do "activation." We asked about this and got the impression from WatchGuard that there is a way around this if you're using it on an isolated network, but that way is not covered in the startup guide (nor is it freely offered by the company's technical support).
Once we got past WatchGuard's system maintenance window and were able to download the Firebox Manager, it wasn't too bad to get through the initial setup. We were advised, though, to not use both the GUI and the CLI since the configs are stored differently. We were told to use one or the other -- a shame since, on so many systems, the GUI is perfect for simple configuration touch-ups while the CLI is there for the heavy lifting. For initial setup, we used the front-panel buttons to give the Firebox an IP address, then connected using the Firebox Manager. You can also do it using the included serial cable to avoid the pain of countless arrow pushes to change the IP address.
Even with the extensive testing (accompanied by the necessary extensive configuration and management that goes with spending weeks on a device's console), we weren't able to work with every single feature on each system. The supercool feature that we couldn't try out on the WatchGuard was the drag-and-drop VPN setup. As long as the console is able to get an encrypted link to both firewalls, you can do a drag and drop from the branch office to the home office for VPN setup.
Speed to burn
With a proxy-oriented architecture such as the Firebox's, you expect to take a hit in absolute packet-passing performance. Typically what you lose in throughput you gain in security, thanks to the proxy's ability to obscure the details of the devices inside the network from the outside world, making it nearly impossible for external devices to connect to them directly. So we were surprised to discover that the Firebox was the fastest UTM in our test -- faster even than the SonicWall, which costs three times as much.
Join the newsletter!
Panasonic OLED 4K Ultra HD TV - TH-55EZ950U
WD MY PASSPORT™ Gaming Storage
Panasonic OLED 4K Ultra HD TV - TH-77EZ1000U
Dyson Supersonic™ Hair Dryer Fuchsia/Iron
Breitling Superocean Heritage Chronographe 44
Bang and Olufsen BeoVision 14
SanDisk MicroSDXC™ for Nintendo® Switch™
Apple iPhone X
WD MY PASSPORT™ X Gaming Storage
Nespresso Creatista Coffee Machine
cloudandco Smart Cane
Toys for Boys
Onyx Smart Walkie Talkie
Lego Mindstorms EV3
Google Daydream View VR Headset
UBTech First Order Stormtrooper Robot
LaCie Rugged USB-C Portable Hard Drive
Propel Star Wars T-65 X-Wing Drone
Leica M10 Digital Rangefinder Camera
Bose SoundLink Micro
Ubiquiti Network’s Front Row Camera
Belkin Pocket Power 10,000mAh
Dearear Endear In-ear Wireless Earphones
Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K
iRobot Roomba 980 Vaccum Cleaning Robot
Nest Protect Smart Smoke Alarm
PETKIG Go Smart Dog Leash
Amazon Echo Bluetooth Speaker
Panasonic Hi-Fi - SC-UA7GS-K
Xbox One X
WD MY CLOUD™ HOME Personal Cloud Storage
Toffee Bags Commuter Satchel
Kogan Bluetooth Soundbar
Razer DeathAdder Expert Ergonomic Gaming Mouse
Fallout Geeki Tikis
Logitech Doodle Collection Wireless Mouse
Tile Pro Bluetooth Tracker
Lexon Flip Alarm Clock
Urbanworx Full HD Action Camera
3SIXT 3-in-1 Smartphone Lens Kit
Raspberry Pi Starter Kit
Panasonic Portable Splashproof Fun - RF-D20U
Ikea NORDMÄRKE Wireless Charging Pad
Most Popular Reviews
- 1 Huawei Mate 10 Pro Review: A solid winter flagship that cribs from the best
- 2 Google Pixel 2 review: not quite 'pixel perfect' but damn close
- 3 Google Home Mini review: a welcome addition to the smart speaker family.
- 4 Huawei Nova 2i review: Flagship features get smuggled into the mid-tier
- 5 Moto X4 review: This is what a world without MotoMods looks like
Latest News Articles
- Kogan hones in on NBN market through Vodafone deal
- BlackBerry wins $815 million in overpaid royalty to Qualcomm
- Extreme swallows Zebra’s WLAN biz for $55 million
- Facebook to begin testing its Internet drone this year
- Apple's Q1: Record $US18.4 billion profit, but iPhone sales are slowing
PCW Evaluation Team
I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.
It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.
Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.
The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.
The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.
The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic
- PC World 2017 Editors' Choice Awards Nomineees Announced
- LG V30+ review: The videographer's smartphone arrives
- Fitbit Ionic review: Impressive but not quite iconic
- What's the difference between an Intel Core i3, i5 and i7?
- Laser vs. inkjet printers: which is better?
Product Launch Showcase
- FTBig Data EngineerOther
- TPBusiness Intelligence Analyst|Software DeveloperQLD
- FTSenior .Net DeveloperACT
- CCGenesys Specialist - SME - TelcoVIC
- FT.Net DeveloperACT
- FTSenior .Net Developer - (Australian Citizens Only)Other
- FTMS Dynamics CRM DeveloperNSW
- FTTelecom Engineer - Network VoiceOther
- CCProject Manager -AgileWA
- FTSenior Power BI Developer, AzureOther
- FTSolution ArchitectOther
- CCChange Analyst-TransformationNSW
- CCBusiness AnalystNSW
- CCProject ManagerACT
- FTOffice 365 SpecialistOther
- CCJunior to Mid Level Tester - BrisbaneACT
- FTPrincipal ConsultantOther
- TPProject ManagerACT
- FTSAP MM ConsultantOther
- CCControl Systems SpecialistACT
- FTDigital BAOther
- FTProject Coordinator / Project Support OfficerSA
- CCProject ManagerQLD
- TPBusiness/Data AnalystQLD
- CCControl Systems SpecialistACT