About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
PRODUCT REVIEWS GUIDE    REVIEWS    ANALYSES    SPECIAL REPORTS 
 

TEST CENTER

 
Big firewall for small offices

By Russell C. Pavlicek
February 22, 2002


SECURITY IS A concern for the entire IT community these days. If a large enterprise with trained security personnel has its hands full trying to secure its network while permitting the Internet services needed to do business, then how can a small or midsize business be expected to do the same? Or how can branch offices of large corporations protect themselves if there are no skilled security administrators on-site?

   ADVERTISEMENT
  

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

RELATED LINKS
»  IE 7 bug reopens debate over patch responsibilities
»  Woman ordered to pay for file-sharing will appeal
»  McAfee to buy SafeBoot for $350M
»  Security RSS feed 

IDG ENTERPRISE NETWORK
Research Reports  (CIO)
Ask the Expert  (CIO)

TOP NEWS 


IT SOLUTION SEARCH
The solution may be a simple firewall and gateway device that installs easily, provides good security, and can be managed from an easy-to-use Web-based interface. The Mitel Networks SME Server V5 is just such a solution.

The SME Server can be deployed quickly by someone who is not an experienced systems administrator. Based on Red Hat Linux, the software is focused on providing a solution that rolls out quickly and requires very little interaction or knowledge on the part of the installer.

SME Server offers an impressive blend of features. For example, the solution can make fine distinctions between the services available on the internal network and those available to the outside world. You can choose to turn on services such as PPTP (Point-to-Point Tunneling Protocol) access or to enable a secure e-commerce Web site, or you can leave your server locked down tight.

The optional ServiceLink feature offers more compelling abilities. For a monthly fee, ServiceLink allows you to combine multiple SME Servers into a single VPN. The normally laborious process of securely exchanging public keys can be done transparently and painlessly, making the creation of VPNs a breeze.

In minutes, branch offices or trusted suppliers can find themselves communicating over a secure, transparent link (provided, of course, each partner has subscribed to ServiceLink).

Another key element of ServiceLink is the virus protection service, which lets you scan incoming mail for viruses and quarantine infected mail as needed.

If desired, SME Server can provide POP3 or IMAP (Internet Messaging Access Protocol) e-mail boxes for the office. It can also provide Web mail access, if your business needs browser-based e-mail.

Another key feature is SME's "information bay" -- a repository that can be used as shared network drives, Web sites, or download sites. This virtual domain can be used to host multiple Web sites on the server or carry out basic administrative functions, such as backup and user account maintenance.

Making life easy

Small shops without skilled network administrators on hand should appreciate SME Server's ease of use. Installation and configuration are straightforward. Pop in the CD, boot up, answer a few questions, reboot, answer a few more questions, and you're up and running in about 30 minutes. The sticking points typically found in Linux installations, such as partitioning and video card support, aren't a problem because of the specialized nature of the solution.

SME Server can be installed on most standard PCs with two common PCI (Peripheral Component Interconnect)-based network cards in about 30 minutes.

To configure the server, simply supply the IP addresses for the network cards as needed (one for the internal network and one for the external network) or instruct your machine to use DHCP (Dynamic Host Configuration Protocol). If you happen to be using a popular dynamic DNS to provide a static domain name to your dynamic DHCP-driven IP address, SME Server can automatically update the dynamic DNS every time your IP address changes, a very nice feature indeed.

If your office does not have a permanent, high-speed connection to the Internet, the server can automatically dial up your ISP as needed. It can even optimize the connection to reduce off-hook time or minimize wait time. Again, those preferences can be set in seconds.

Similarly, administering SME Server requires almost no heavy lifting. The system administration Web interface is appealingly simple, obviating the need to edit command files or master arcane Unix-style commands. The system can run as a strongly configured firewall and gateway right out of the box, and if you ever need to modify settings, the Web interface enables you make to adjustments simply and easily.

Finally, new software, in the form of "blades" offered periodically by Mitel Networks, can be reviewed, downloaded, and activated with just a few mouse clicks, making security upgrades a breeze.

Mitel's blades boast functionality ranging from security upgrades to MP3 jukeboxes -- just the ticket for companies that want to stay on top of the latest security developments but can't afford the expense of a full-time security expert.

Granted, a seasoned security administrator could do an even more thorough job of locking down a firewall. For example, the /usr directory tree could be moved to a read-only partition, which would give crackers less of an opportunity to do damage if they should find holes in your network. Then again, doing so would also increase the complexity of performing security updates.

And that's the trade-off. SME Server probably isn't the best solution for large companies because it doesn't offer the most robust functionality on the market, and because trained security personnel probably don't want menus insulating them from the nitty-gritty details of security administration. On the other hand, SME Server can be rolled out quickly and it won't ask you for constant baby-sitting when it's active. That makes it tough to beat for satellite offices or smaller businesses.


Russell Pavlicek (pavlicek@linuxadvocacy.net) is an open-source author and consultant.



  BOTTOM LINE
Mitel Networks SME Server V5
BUSINESS CASE
This is a simple but effective firewall and gateway solution. It is a very good choice for businesses that cannot afford to hire security administrators for each office.

TECHNOLOGY CASE
SME Server can lock down specified services, both internally and externally, straight out of the box. Software blades with added functionality (such as security updates) can be easily downloaded and installed.

PROS
+ Simple to administer
+ Provides very good security
+ Includes e-mail and optional VPN service
+ Low cost

CONS
- Not appropriate for large enterprises

COST
Free download; $175 per month for ServiceLink option

PLATFORMS
All TCP/IP-based clients

COMPANY
Mitel Networks; www.mitel.com

Deploy
Ease of use
Implementation
Innovation
Interoperability
Scalability
Security
Suitability
Support
Training
Value
Deploy



RELATED SUBJECTS

Security
Networking


SPONSORED WHITE PAPERS
EMC - Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust - Are you ready for Sobig.G? Learn how to protect your email systems.
CDW - Personal attention. CDW. The Right Technology. Right Away.
EMC - Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel - Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco - FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc. - "Mass Consolidation Hits the Web-Search Market"
McDATA - Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies - Overcoming Common Firewall Limitations
Lucent Technologies - Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia - Get the scoop! Mobilizing business white papers & case studies.
BMC Software - Maximize the Potential of Enterprise Data: Free white paper!
Network Associates - Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust - Manage identities across applications. Improve productivity.
Stalker Software - CommuniGate Pro - Transform your Email and Calendaring
Remedy - A NEW Gartner Research Note:Producing Quality IT Services

Search the IDG White Paper Library:


SPONSORED LINKS

INFOWORLD MARKETPLACE


» IT Compliance Conference: Nov. 5-7 in San Diego
Best Practices, Peer Experiences, & Expert Advice for Building a Defensible IT Compliance Program
» FREE Sophos Threat Detection Test
Is your AV catching everything it should? Free virus, spyware and adware scan.
» IT Audit Checklists
Prepare for your next internal IT audit. Checklists cover security, risk management, PCI, and more.
» FREE White Paper: Mitigating Rock Phish Attacks
Standard anti-phishing methods cannot defeat complex Rock Phish attacks. Learn how to fight back...
» Apply BPM and ITIL at your IT Help Desk
ServiceWise brings BPM to complete IT service while eliminating integration cost. Learn more here.




 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2009, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no