VPN performance evaluation: Which device performs the best data segmentation into packets, encrypted and sent over VPN channels. Testing Spirent Communications' TeraVPN version 4.0 toolkit installed on SmartBits 600 (SMB-600) installed 2 TeraMetrics XD communication cards, each card has a 10 / 100Mbps port.
• First, just run a VPN channel to make sure VPN works, then increase it to 20 channels. A small or medium sized business with 100-200 employees usually only needs up to 20 concurrent VPN connections. First, create 20 stage 1 channels (IKE), then in each channel create a stage 2 channel (IPSec). For the first time, to keep the packets fixed at 1024byte, the next time we change the capacity of the packets from 64byte to 1350 bytes, each step is done 50000 times.
• Evaluate basic firewall functions: Use Spirent's Avalanche / Reflector software on SMB-600 to create attacks. First, open up small DDoS attacks on each firewall to see if they detect and react, at least to sound an alarm. EdgeForce Plus, NetScreen and Safe @ Office work very well, they not only warn but also start eliminating attack packets. After that, continue to use stealth attack, how to ping the firewall. Conclusion: as long as the user is set up correctly, firewalls can prevent normal attacks.
• Anti-virus assessment: Set up a Linux server running Sendmail outside the firewall to send virus packets to a series of computers running behind the firewall.All viruses are simulated codes provided by the European Computer Virus Research Institute.All devices that pass this test are very smooth, but not all anti-virus for users using IMAP protocol.
The only feature not found on other devices is NetScreen's source routing capability.All tested devices allow for static routing, but only NetScreen can add 'source routing' declarations, so that users know where the route comes from and where the source comes from. OSPF (Open Shortest Path First), RIP (Routing Information Protocol), Boundary Gateway Protocol (BGP) or static routing.This is really the function of a high-end firewall integrated into an easy-to-use device.
Sonicwall PRO 2040
This medium-sized enterprise firewall can meet all requirements, it is easy to spot this when taking the device out of the box, it can be placed on a table, on a shelf, or installed in a 1U rack. All right.SonicWALL Pro 2040 combines SonicWALL's new generation SonicOS operating system and a good load-bearing hardware architecture, as long as you configure it correctly, of course, not simple.
PRODUCTS IN THE VIETNAMESE MARKET
Security is currently a 'hot' issue in our country, so if you are interested, you can find out the product information of the companies that are officially present in Vietnam through distributors.
Check Point: MISOFT (08-844 3027, 04-933 1613);Juniper: Juniper Networks Vietnam;SonicWALL: ITC JSC (04-943 0724, 08-925 3304).We tried to contact these distributors to ask for selling prices in Vietnam.However, until this article is printed, only Check Point product information: Safe @ Office 105: 614 USD, Safe @ Office 110: 1,071 USD, Safe @ Office 225: 1,887 USD, Safe @ Office 225U: USD 2,980.(information provided by MISOFT).Price does not include VAT, installation and deployment fees.Customers receive technical support during the process of using the product.
When used, users must install the SonicWALL extension OS to exploit many advanced features such as connecting to multiple ISPs for redundancy, load balancing with other Pro 2040s, setting NAT based policy and Redundant WAN connection.
Although Pro 2040 can be operated without the SonicOS Enhanced operating system, but you must install this OS to enable the device's fourth communication port.This port can function as a WAN, LAN, or DMZ port, or connect to another Pro 2040 device for backup.SonicWall is not inferior to rivals, it also integrates virus prevention and content filtering functions.
Pro 2040 is quite satisfying, for example, it is equipped with a processor that only makes each encryption task so the performance is no different when using AES-256 or 3DES encryption mode.A series of simulated attacks as well as preventing viruses when tested are prevented by this firewall.However, for the price of 1995 USD (price in the US), Pro 2040 should have more attractive features than NetScreen-5GT, the price is only 495 USD
Quoc Thanh
Infoworld