Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

UTM appliances whip blended security threats

Unified threat management appliances combine multiple perimeter protections with mixed results


All of the expected security services are in the 400A, and as opposed to Astaro and WatchGuard, Fortinet allows anti-virus scanning to be assigned to traffic other than SNMP. Services are enabled and assigned specific actions in a Protection Profile. Profiles can be a specific mix of services tailored to a type of traffic. For example, I created a profile only with anti-virus and IPS enabled and used it as a protection policy for FTP traffic. Admins can create many different profiles, each for a specific need. 

Return to special report

DOWNLOAD PDF

Click here to download InfoWorld's special report UTM appliances


The anti-virus service, although better than most, has its limitations. There is an upper limit on the maximum file size that can be scanned as it passes through the FortiGate. If the file exceeds 50MB — the upper limit for the model I tested — admins have the choice of denying the transfer completely or ignoring the oversized file and passing it without scanning it. This size limitation applies to all forms of traffic.

Fortinet maintains its own signature lists for anti-virus, IPS, Web, and spam filters, and updates can be scheduled hourly to make sure the latest definitions are online. In addition to signatures, the IPS uses anomaly detection to protect exposed systems. Admins can create custom signatures or simply use the included list. As with all of the solutions tested here, Core Impact couldn’t find a crack in Fortinet’s IPS.

Reporting and logging services are average. Five different logs are included, but for the best results, admins will want to ship the information off to either a Syslog or WebTrends server. For centralized management, Fortinet’s FortiManager is the platform to use. It allows for direct remote management as well as report and log aggregation.

ServGate EdgeForce M30

ServGate’s EdgeForce M30 appliance comes with three 10/100Mbps interfaces and a 20GB hard drive used for Web caching and many of its core security services. Setup and configuration of the M30 was straightforward; I had the unit online with a default outbound policy in less than 30 minutes. The M30 came in as the lowest-cost appliance in our group, and policy creation and maintenance were not overly difficult.

The M30 is based on purpose-built hardware. At its heart is a stateful inspection firewall that provides good all-around protection. As do Fortinet and WatchGuard, ServGate provides dynamic routing, such as RIP v1 and v2, and static routing, as well as dynamic DNS. QoS is included, but it isn’t nearly as complete as the support found in Fortinet. VLAN support will be available in the next release of the ServGate OS.

VPN services are also well supported with various flavors of site-to-site IPSec and PPTP, and ServGate’s VPN client handling client-to-site chores. Admins can choose between cipher strengths up to 3DES and AES256.

Creating inbound policy for my protected resources required first defining a virtual IP alias for each service and then plugging them in to the appropriate IP mapping policy. Part of the policy creation includes what content filter to apply to the inbound traffic. ServGate’s content filters are based on IPS rules and the additional security services such as anti-virus.

For example, I was able to create a “test” content filter for my exposed Web server using a predefined Web server IPS policy and then by choosing to add anti-virus filtering. Admins can use the canned IPS and content filter rules or create new ones to meet specific needs. My only complaint is that I had to hop among three different areas of the admin console in order to manipulate and assign a content filter.

The security services available in the M30 are very good, using a mix of best-of-breed and in-house developed services. For anti-virus and anti-spam, ServGate uses McAfee’s scanning engines. For Web filtering, SurfControl is included. All licensing for these third-party tools is handled by ServGate and included in the total price. Because the M30 has a local hard drive, files and messages can be quarantined instead of simply discarded.

As opposed to WatchGuard’s Firebox Core, ServGate’s EdgeForce M30 provides anti-virus scanning for SMTP, HTTP, POP3, and FTP traffic. The M30 passed my anti-virus test with flying colors, managing the 160MB file transfer and stripping out the virus.

Keith Schultz is contributing editor of the InfoWorld Test Center.
Continued
« PREVIOUS PAGE | 1 | 2 | 3 | 4 | 5 | NEXT PAGE » 

 The Bottom Line

Astaro Security Gateway 220
Astaro, astaro.com

Very Good  8.0
criteria score weight
Firewall/VPN 8 25%
UTM services 8 25%
Management 8 15%
Reporting 8 15%
Setup 8 10%
Value 8 10%

Cost:
$2,550 for hardware and all services licensed

Bottom Line:
The ASG 220 provides good all-around firewall and UTM protection. Astaro doesn’t make policy definition as easy as its competitors do, but its UTM services are on par with the competition except for one shortcoming: There is no anti-virus scanning of FTP traffic in the current release. VPN features are well done, as are the reporting and remote management tools.

About our Reviews and Scoring Methodology

 The Bottom Line

Fortinet FortiGate 400A
Fortinet, fortinet.com

Very Good  8.4
criteria score weight
Firewall/VPN 9 25%
UTM services 8 25%
Management 9 15%
Reporting 8 15%
Setup 8 10%
Value 8 10%

Cost:
$8,495 for hardware and all services licensed

Bottom Line:
The FortiGate 400A is a solid all-around performer with a well-crafted firewall and policy engine, solid VPN ­features, and powerful and flexible routing capabilities. UTM features are also very good, although virus scanning is limited to 50MB files and smaller. Logging and reporting could use a face-lift, and the price tag is comparatively steep.

About our Reviews and Scoring Methodology

 The Bottom Line

ServGate EdgeForce M30
ServGate Technologies, servgate.com

Excellent  8.7
criteria score weight
Firewall/VPN 9 25%
UTM services 9 25%
Management 8 15%
Reporting 8 15%
Setup 9 10%
Value 9 10%

Cost:
$1,095 for hardware and all services licensed

Bottom Line:
The EdgeForce M30 is one of the better UTM appliances we’ve tested. Despite the low cost, it doesn’t sacrifice any features. Policy management is straightforward, VPN services are solid, and the UTM services work well. ServGate’s Global Manager does an excellent job of remote management, although local log files can be hard to sort through.

About our Reviews and Scoring Methodology

 The Bottom Line

SonicWall Pro 2040
SonicWall, sonicwall.com

Excellent  8.9
criteria score weight
Firewall/VPN 9 25%
UTM services 9 25%
Management 9 15%
Reporting 8 15%
Setup 9 10%
Value 9 10%

Cost:
$2,665 for hardware and all services licensed

Bottom Line:
The SonicWall Pro provided the best all-around mix of features and functionality among the appliances in the roundup. Setup and policy creation are straightforward and easy to do. The UTM services, although not as granular as those of other appliances, work across all types of traffic in all situations. Reporting is the one weak spot, requiring external apps to get the most out of it.

About our Reviews and Scoring Methodology

 The Bottom Line

WatchGuard Firebox X2500 Core
WatchGuard Technologies, watchguard.com

Very Good  8.3
criteria score weight
Firewall/VPN 9 25%
UTM services 7 25%
Management 9 15%
Reporting 9 15%
Setup 8 10%
Value 8 10%

Platforms:
WatchGuard Firebox X2500 Core

Cost:
$4,990 for hardware and all services licensed

Bottom Line:
The Firebox X2500 Core UTM appliance comes with a very strong policy engine based on packet filters and application proxies. Its IPS and VPN services leave nothing out, UTM services are very granular, and WatchGuard has possibly the best monitoring and reporting packages available. On the downside, virus scanning doesn’t reach across all traffic types.

About our Reviews and Scoring Methodology


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





Virtualization: A Step by Step Approach to Success
Your virtual machines can be up and running in a matter of minutes. HP and Citrix have integrated XenServer with HP ProLiant servers and management tools, powered by hardware-assisted Intel Virtualization Technology to enable high- performance, cost-savings solutions for server consolidation and disaster recovery. Sponsor: HP

»  Click here to view this Webcast
  Planning For A Disaster
This new, comprehensive Solutions Guide is your one stop source for Disaster Recovery. In it you'll learn how to reduce the likelihood of a disaster and to create a rock solid business continuity plan should you face a disaster situation. Sponsored by Equallogic

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 08/29/2008

Microsoft will focus on performance issues in Windows 7 and IE8, Qualcomm...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist