I'm evaluating using Wingate for a medium sized organisation (~800 staff). So far i'm quite impressed with the setup of the WinGate product. We're currently running ISA 2004 and looking for a replacement. it was going to be a no brainer to TMG until Microsoft discontinued that product :(
So far WinGate appears to be able to replace our ISA servers from an explicit proxy point of view, and is a lot cheaper than the appliances I've looked at so far.
We also have a parallel project looking at tracking usage within a wifi network provided for staff to use with their own devices. At this stage we're not looking to require authorisation, however we would like to be able to track the volume of traffic per device to help track down abusers of the system. This would ideally be through a transparent proxy.
At this stage I have a couple of questions for each project i was hoping to enquire about. Please forgive me if these are answered elsewhere in the forums or help files.
- As I'm not yet able to load test the product, do you have any estimates on maximum users per server/cpu? or just any performance metrics in general?
I understand this would be impacted by the rules in place and user's browsing habits. - If I was to deploy multiple WinGate servers, is there any way to syncronise the configuration of them all? eg to keep data lists and rules/policies consistent
- When an SSL connection is made, i know you can't inspect the URL etc (without providing a signing certificate), but is there any way to capture the amount of traffic for volume/bandwidth per source IP/MAC tracking?
- I've found the IP black hole feature, is there a similar MAC/Physical Address blackhole? Or should this be implemented as a new policy performing a data list lookup?
- What support options are offered by qbik? As we would rely somewhat on the ability to browse through the proxy, downtime would not be favourable :)
Thanks,
Ribs.
(edit - changed subject to remove intercept reference)