Reviews - Channel Insider
Empowering the next generation Channel
 

Bull’s Eye Awards
Nominations Open for Channel Insider 2009 Bull’s Eye Awards
Nominations are now open for the Channel Insider 2009 Bull’s Eye Awards, which recognize excellence in customer service, technology prowess, business acumen, channel leadership, communications and community building, and innovation among vendors, solution providers, distributors and channel services companies.



Sponsored Links
  • Control VM Sprawl, What You Don’t Know Can Hurt You
  • FREE Sophos Encryption Tool: Encrypt, compress and share files easily
  • LSI 6Gb/s Portfolio Expands to Include SATA+SAS HBAs
  • Reduce the cost of managing your mobile workers.
  • Find out 7 Ways to Drive Data Center Efficiency
  • SonicWALL breaks through network and email gridlock
  • Save up to 40% on calling costs with Avaya Aura™



  •  

    ZyXel Security Appliance Does More for Less

    in Reviews


    Article Rating:starstarstarstarstar / 0
    Article Views: 1311

    Rate This Article:
    Add This Article To:
    Review: ZyWall 1050 provides a robust firewall and VPN capabilities for a relatively low price.

    ZyXel Communications' ZyWall 1050 puts advanced network security in the hands of small and midsize businesses.

    The ZyWall 1050 is a 1U (1.75-inch) Internet security appliance that provides firewall protection, a 1,000-tunnel VPN option and a host of traffic control features for governing internal users.

    Announced in October, the ZyWall 1050 costs $4,000. Although this is on the higher end of the price scale for this class of security tool, the ZyWall 1050 packs five Gigabit Ethernet ports—the most we've seen in this class of security appliance.

    During eWEEK Labs' tests, the ZyWall 1050 effectively repelled automated probes from our Metasploit attack system. It also withstood tests using malformed IP traffic streams generated by a test device we've just started using: the Mu Security Mu-4000 Security Analyzer.

    We also put the ZyWall 1050 on our outside Internet connection to let it fend off probes and scans from the outside world, which it did with aplomb.

    Resource Library:
    ZyXel offers many add-ons for the ZyWall 1050, including the IDP (intrusion detection and prevention) engine and a content filter. We used both components during our initial tests.

    The IDP engine is an embedded, signature-based component that is turned on with a license key. Many security advisers point to the weaknesses of signature-based protection in a world of zero-day threats, and we generally concur. However, security for a smaller organization must be based on a careful risk analysis that balances the cost of security with actual threats, and the ZyWall 1050 IDP engine provides good protection for the price.

    During our tests, the signatures that look for protocol anomalies and pattern matches were updated several times by ZyXel's security response team. These updates can be applied automatically, which is what we recommend for busy IT managers in smaller organizations that may not have the staff to review the new signatures.

    None of the updates blocked our good test traffic. However, there wasn't a good way to roll back the updates. This means that IT managers who get a false-positive block resulting from a newly installed update will likely spend a fair amount of time adjusting the signatures by hand.

    eWEEK Labs picks the top five network security developments of 2006. Click here to check them out.

    The ZyWall 1050 provides a fine level of control over individual user access, and we could add authentication requirements for the network, including the maximum number of log-on retries and the length of time a user should be locked out if log-on fails.

    However, there is no way to integrate user information with a directory such as Microsoft's Active Directory. This means that IT administrators will be managing user accounts from the console. We hope that subsequent versions of the ZyWall 1050 include an option for integrating with existing directory data.

    Always On

    The ZyWall 1050 provides high availability in two ways.

    The appliance can use multiple WAN ports to create backup connections in a single device. During tests with the single-device scenario, the WAN backup connections worked to load balance and provide failover if WAN services were offered by different providers. The ZyWall 1050 also can use VRRP (Virtual Router Redundancy Protocol) to link two ZyWall 1050s—an impressive capability given the appliance's price.

    The combination of WAN backup and VRRP device redundancy means that IT managers can realistically deploy the ZyWall 1050 in locations where mission-critical applications are used.

    Voice traffic gets special treatment from the ZyWall 1050. We configured our device to enable SIP (Session Initiation Protocol) transformations, and we could specify additional SIP signaling ports. There is even support for much older H.323 VOIP (voice over IP) traffic. The voice traffic pass-through features worked well in our tests, and after spending a couple of hours configuring the settings, we were able to get voice traffic through the firewall.

    Technical Director Cameron Sturdevant can be reached at cameron_surdevant@ziffdavis.com.



    Discuss ZyXel Security Appliance Does More for Less
     
    >>> Be the FIRST to comment on this article!
     

     
     
    >>> More Reviews Articles          >>> More By Cameron Sturdevant
     


     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    Enterprise Mobility Zone
    The Enterprise Mobility Zone (EMZ) blog is a tool designed to help senior IT executives discuss, create and deploy next-generation mobile strategies in their organizations.
    Go beyond yesterday's tactical approach to mobility!
     
    Build A More Efficient Data Center
    Demands are growing but budgets are not. Solve your pressing IT issues using the resources you already have. Determine which technologies can help you drive efficiencies and how they are applied. Gain a quick ROI on new initiatives
    Find out how
    Let Enterprise TechBrief do the work for you. Aggregated content, tech news, product reviews, vendor updates, how-to’s—all you need to boost your efficiencies and cut costs, all from one place.
    enterprisetechbrief.com