Limitations of NG Firewall

From Edge Threat Management Wiki - Arista
Jump to navigationJump to search

No software is perfect, and no solution is right for everyone.

The goal of this page is to be up-front and realistic about some common complaints about NG Firewall. This may help you save some time and determine if NG Firewall is ultimately right for you.

Simplified Settings

We strive to keep things simple and not introduce more settings than necessary. We want things to "just work." However, this is not right for everyone – for example, power-users who like to customize and tweak settings. For example, power-users coming from other solutions might be frustrated by not being able to tweak the spam engine's inner configuration or how the web filter categorizes sites. We strive to make NG Firewall powerful yet simple. Sometimes this involves not implementing or hiding advanced features and dangerous settings that can do more harm than good. Whether NG Firewall's approach is right for you or not depends on your goals.

Community Support

NG Firewall users without a support subscription are supported mostly by the community on the forums. Arista Edge Threat Management staff and the community strive to provide the best help possible on the forums. However, the community is not obligated to help you. They do so on their own time and at their own expense. You are not entitled to free support on the forums, from the community nor from the Arista Edge Threat Management team. Your ability to get help from the community and forums is highly correlated with asking the question in the correct way and responding to their questions.

Arista engineers and Product Management team members do monitor the forums and can help when time permits.

Dangerous Features

NG Firewall includes many "antifeatures" that can cause problems and degrade the product experience. Despite our Simplified Features philosophy, these features and functionality are included because many users consider them to be "must-have" features. Like other configuration in NG Firewall enabling these features is easy and does not require command line changes or reading the documentation, but that does not mean they are safe or recommended. Some apps like Web Cache, Ad Blocker, and Intrusion Prevention can cause problems and/or slow network traffic; other individual settings can be dangerous. Edge Threat Management staff can only recommend settings. Ultimately the admin controls the configuration, and if the admin insists on misconfiguring NG Firewall then it may not perform optimally.