This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Runing Sophos UTM virtualized or on dedicated hardware?

Hi!
I have a computer with a Core I7 2600K, 32GB ram, 4 Intel nics, and I'm planning to run Sophos UTM on this as my primary firewall (home use with some internal and some public servers behind).

I think it is quite a waste to use the hardware as a firewall only, I don't think Sophos need an I7 with 32GB ram, or am I wrong?

I have a little thought to run ESXI on the machine to have some more vm:s running on it in parallell with Sophos UTM.

I think the hardware can handle a one or two vm:s alongside a Sophos install..?

 

My biggest concern are the security, how secure is it to run the firewall virtualized? For some reason my heart screams a little when I'm thinking to run it virtualized, because
a dedicated approach should be more secure, because you don't expose a virtualization platform to the net as you do with a virtualized approach.

But is it common that hackers find holes on the virtualization platform and can gain access to the internal lans? How safe are virtualization platforms nowadays?

I don't think it is an uncommon approach on companies to run it virtualized, but maybe I'm wrong. This is for personal use in a home environment, but I still want secure networks.

I may run it virtualized if you say that it is safe.. :P

 

For your information: I have a 250/100Mbps fiber connection to my house.

 

Thanks in advance!



This thread was automatically locked due to age.
  • David,

    In full respect of your knowledge and wisdom, I think this thread has moved upon it’s purpose, and is now more confusing as each answer raises hundreds of questions, I think Widde has something to work with now, and theese long ongoing responses is not helping further out.

    Should we not call this a day ?

    ;)

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v20 Technician

  • One thought to consider. I went through this 3 years ago. I have 2 vmware servers that I enjoy playing with.  I found that my UTM firewall in a VM was more of a pain to keep sorted out as far a ESXi went. Hardware and software changes.   

    I made a small dedicated computer with 6 ether ports and have never again thought about making it into a VM again.  The dedicated box once setup just works and I don't play with it's hardware, unlike ESXi. You want your first line of defence to be stable and not a lot of work. I use a dual core G 3258 cpu 4 GB ram. I can plug any 1150 socket cpu in if I need more power, but I don't.  It might cost more for dedicated hardware but in 6 years it will a drop in the bucket for the use you get out of it. I used a supermicro ITX server board. It will last me a long time.

    What ever you do, have fun doing it.