generally speaking.....
Say, In an approx 10-20 user network
Im wondering how to justify the cost of lower end hardware firewalls : $1500+ ongoing maintenance plans + costs of annual licensing
A descent router has some basic firewall funtionality built in, eg NAT, SPI, some even have basic content filtering
Many routers also support site to site VPN's .
Is a hardware firewall justified on small networks ? Given the initial cost & ongoing annual support costs & licensing costs .
Sure , allways better to have than not have, but do the lower end hardware firewalls do enough to justify the cost ?
Ive read some of the 'advertising' about what they claim, but if you block all ports except those needed , then what else does the hardware firewall provide (I know they do drop port scans, but then stupidly allow the same IP to port scan again some time later)
Im also not conviced the optional security bundles for the hardware , that you pay annually for, do that much either , on the cheaper units.
All the security issues Ive seen are from staff stupidity , and the Firewalls didnt help there at all (sort of as expected).
We have clients with old firewalls, I'm just considering upgrades to new Firewall hardware , over something like a cheaper Draytek 2820 .
With the move to fibre, the older firewalls may be a bottleneck (but still usuable )
one client told me to look for cheaper options , some others will take some convincing to upgrade the older Firewalls .