Reviews - Channel Insider
Empowering the next generation Channel
 
Bull’s Eye Awards
Nominations Open for Channel Insider 2009 Bull’s Eye Awards
Nominations are now open for the Channel Insider 2009 Bull’s Eye Awards, which recognize excellence in customer service, technology prowess, business acumen, channel leadership, communications and community building, and innovation among vendors, solution providers, distributors and channel services companies.



Sponsored Links
  • SonicWALL breaks through network and email gridlock
  • Save up to 40% on calling costs with Avaya Aura™
  • HP PartnerONE | SolutionsINFINITE Visit us at hp.com/partners/us/go/4



  •  

    F5 Secures Remote Access

    in Reviews


    Article Rating:starstarstarstarstar / 0
    Article Views: 1407

    Rate This Article:
    Add This Article To:
    F5's FirePass 1000 appliance secures remote access, but it's pricey and needs polish.

    Although F5 Networks Inc.'s initial foray into security appliances is a little rough around the edges, its FirePass 1000 has the potential to provide a flexible, powerful, SSL-based remote access solution for organizations looking to avoid IP Security's administrative hassles albeit at a hefty price.

    The FirePass 1000's price starts at $9,900 for 25 concurrent users or at $19,990 for a maximum of 100 concurrent users. At almost $200 per user for 100 users, this price is steep compared with that for many SSL (Secure Sockets Layer) and IPSec VPN solutions. Companies with greater needs should consider the FirePass 4000, which supports as many as 1,000 users for $69,990 and can be clustered for even greater demand. Both units began shipping in late October.

    SSL-based VPNs present a clear advantage over IPSec to overworked administrators, requiring little or no client configuration. Using the FirePass 1000, clients can interact securely via SSL: The FirePass decrypts and proxies transmissions to the proper host on the protected network. Indeed, the FirePass requires remote users have nothing more than an HTTPS (HTTP Secure) and ActiveX- or Java-enabled browser and an Internet connection to access corporate applications and data.

    Resource Library:
    EXECUTIVE SUMMARY
    FirePass 1000

    F5's FirePass 1000 SSL VPN provides excellent security and easy access for remote users accessing the corporate network. The product institutes a tiered approach to network access, using policies that account for user and group permissions, location, and client software. However, some features behave inconsistently according to the Web platform being used. Pricing for 100 concurrent users is a relatively steep $19,990.

    KEY PERFORMANCE INDICATORS
    USABILITY FAIR
    CAPABILITY GOOD
    PERFORMANCE GOOD
    INTEROPERABILITY GOOD
    MANAGEABILITY GOOD
    SCALABILITY FAIR
    SECURITY EXCELLENT
  • PRO:Tiered approach to network access depending on client credentials, user install rights and administrator-defined group policies; supports many applications with native client software or within the browser frame.

  • CON:Confusing layout complicates creating a single group's policy; cannot cluster units; inconsistent behavior of the drive-mapping feature; pricey.
  • EVALUATION SHORT LIST
    Aventail EX-1500 Neoteris' Access 1000 (recently purchased by NetScreen Technologies Inc.)

    A few network services (intranet, e-mail and terminal host access) can be viewed clientless in the browser frame; others can be viewed via a thin client configured via the appropriate F5 Webifyer ActiveX component or Java plug-in—Windows drive mapping and Terminal Services are notable. To use an organization's existing client software, administrators can define an appropriate, single-application F5 AppTunnel back to the server. We liked the flexibility the latter feature provides, although we did have to point the client application to a loop-back address that is presented to the user in a pop-up box, which can cause some confusion. The FirePass also offers full network SSL VPN access for applications, such as voice, that require a wide range of ports.

    The FirePass' ActiveX cache-cleaning utility, which ensures any relevant data is removed from the remote browser cache, distinguishes it from competing products from Aventail Corp. and others. But customers implementing client security with JavaScript on their intranet applications may prefer the Neoteris Access 1000 product because the FirePass requires workarounds to reverse-proxy these applications correctly.

    In eWEEK Labs' tests, we placed the FirePass in our network's DMZ and configured our firewall to pass the service with the protected servers. We culled user and group information from our Active Directory via an LDAP call and configured the FirePass to authenticate to our domain for each user log-in attempt. The FirePass can also authenticate to RADIUS (Remote Authentication Dial-In User Service) servers and Windows NT domains, or it can use an internal database.

    The FirePass' powerful policy engine allowed us to define different access rights for each group, but keeping track of Web-based configuration pages for multiple groups can be difficult. We'd prefer that F5 add a group-centric viewing option allowing us to see a single group's entire policy, instead of having to click through each Webifyer individually.

    More impressively, the FirePass let us control access depending on the relative security of the client machine. The FirePass supports kiosks where the user has no rights to install ActiveX or Java plug-ins, limiting access to intranet or e-mail traffic only. As mentioned above, administrators can also limit access to sensitive applications by requiring a client-side certificate and appropriate anti-virus and firewall security software—although we believe deploying client certificates to end-user machines reduces some of the advantages inherent in SSL VPN technology.

    The FirePass supports an array of browsers, with the flexibility to tailor the user experience by platform. However, certain features were inconsistent across platforms, particularly the drive-mapping Webifyer. F5 officials attributed this flaw, along with other interface irregularities and rare system lockups, to the late-beta software in our test unit. These issues should not dissuade administrators from further investigating the shipping product.





    Discuss F5 Secures Remote Access
     
    >>> Be the FIRST to comment on this article!
     

     
     
    >>> More Reviews Articles          >>> More By Andrew Garcia
     


     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    How to Unleash Application Performance with Solid-State Drives and Sun Servers
    Unleash the Beast! Learn from Sun and Intel experts how Sun servers equipped with Flash-enabled solid-state drives offer dramatic improvements to HPC, Web 2.0, and data center application performance Watch this video to learn more
    Watch Video
     
    Build A More Efficient Data Center
    Demands are growing but budgets are not. Solve your pressing IT issues using the resources you already have. Determine which technologies can help you drive efficiencies and how they are applied. Gain a quick ROI on new initiatives
    Find out how
    Easily Monitor Virtual, Physical, and Cloud based assets, applications and services from a unified Dashboard with up.time. Deep Monitoring across platforms and best-of-breed reporting. Over 700 enterprise customers in 32 countries.
    Read Article