home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



  S N E A K  P R E V I E W

Long Live the Nokia IP650żA Noteworthy Firewall Appliance

February 7, 2000
By Greg Shipley

As a seemingly end- less onslaught of network appliances continues to saturate the market, only a few vendors have produced entries worth noting. One of those offerings is the Nokia IP650, a turnkey firewall appliance that will leave its mark on the firewall industry.

Based on the Unix-derived Nokia IPSO operating system, running on an Intel Pentium II platform, the IP650 comes bundled with Check Point Software Technologies' popular firewall product, FireWall-1.

Although some people might question the allure of an appliance-based approach, anyone who has been under the gun supporting mission-critical firewalls when one of them decides to keel over will most likely jump on this bandwagon. The IP650 has several advantages over traditional firewall installations. The two that stand out are a simplistic approach to restoring failed units and a prehardened, as well as prepatched, operating system. It should be noted, however, that such benefits come at a price: Nokia releases recompiled versions of FireWall-1 only after official Check Point releases. This delay puts Nokia builds of FireWall-1 a little behind on the upgrade cycle, though in the past Nokia customers have been shielded from bugs Check Point has missed.

Although the Nokia IP650 has been shipping for some time, it took us a while to get our hands on one. But as soon as I received the unit, I began its integration into our production network. Unfortunately, replacing the existing Cisco Systems PIX firewall proved to be a bit more challenging than I had anticipated, primarily because of some ambiguous documentation that shipped with the IP650. But I'm not sure I can blame Nokia for this one: It seems the entire computer industry has gone the route of cheap labor when it comes to accurate documentation efforts.

Voyager Takes Flight
Once I had the IPSO image installed, I was able to access the unit via its Network Voyager Web-based interface. Network Voyager serves as the primary method for configuring IPSO and the Nokia unit. It does not, however, replace the Check Point-supplied administrator GUIs. From Network Voyager I was able to configure everything from routing protocols to interface addressing to VRRP (Virtual Router Redundancy Protocol) options. The IP650 supports OSPF, RIP, IGRP (Interior Gateway Routing Protocol) and BGP (Border Gateway Protocol). This is quite a refreshing approach to firewall management, and I think most administrators will take to it fondly. However, I was a little disturbed by the lack of SSL (Secure Sockets Layer) support when accessing the Network Voyager interface. I was forced to log in over plain HTTP, transmitting user names and passwords unencrypted. Nokia informed me that the credit for this "feature" (or lack thereof) goes to U.S. encryption laws.

Fortunately, command-line junkies and paranoid administrators will take comfort in the fact that the IP650 does come with an ssh daemon, and you can use Lynx to access the Web interface over an encrypted ssh tunnel. This combination avoids the clear-text password issues, but isn't as aesthetically pleasing. After I completed the initial IPSO configuration, I moved on to the FireWall-1 configuration. This was fairly painless after I shredded the remaining traces of the Nokia-supplied documentation that had led me awry. Once the Check Point firewall module was installed and configured, I pushed a firewall rule set to the unit from my Check Point firewall management console, just as you would with any other Check Point FireWall-1 platform. The IP650 appears to integrate into existing Check Point environments seamlessly.

Fit and Trim Design
ISPs and organizations operating remote offices will particularly like the IP650's compact and modular design. The back of the 2U-sized unit allows for redundant power supplies, while the front of the unit supports hot-swappable hard drives and an assortment of other cards. The unit I tested came with a quad Ethernet card and a removable PCI drive, and there were still four slots to spare.

Another plus is the fact that I could rebuild and reconfigure a firewall in about 20 minutes--the time it takes to restore the IPSO image and configuration files from the network. For anyone who has gone through the mind-numbing process of installing an operating system and then the 10 billion service packs, hot fixes or patches, the IP650's rebuild--simplicity in itself--comes as a welcome surprise. Upon hardware failure you simply slap in a replacement part, or even an entirely new IP650 unit, restore the IPSO image and the firewall rule set, and you're ready to go.

The IP650 also boasts a wide range of interface types--everything from token ring to ATM to actual CSU/DSU and v.35 support. Nokia also claims to do some high-availability VPN (virtual private networking) support. With a Pentium II under the hood, a solid OS, and an industry-standard firewall package, the IP650 is a real workhorse. I think our Cisco PIX just "got lost."

Greg Shipley is a Chicago-based consultant. Send your comments on this article to him at gshipley@neohapsis.com.



 





Looking for a new job?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
The tumbling of IT jobs stopped in the second quarter, as the IT sector added about 44,000 jobs.

It's just a glimmer, but Oracle is starting to see a bit of light at the end of the recession tunnel.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service