![]() |
|
| S N E A K P R E V I E W | |
Long Live the Nokia IP650A Noteworthy Firewall Appliance February 7, 2000 By Greg Shipley As a seemingly end- less onslaught of network appliances continues to saturate the market, only a few vendors have produced entries worth noting. One of those offerings is the Nokia IP650, a turnkey firewall appliance that will leave its mark on the firewall industry. Based on the Unix-derived Nokia IPSO operating system, running on an Intel Pentium II platform, the IP650 comes bundled with Check Point Software Technologies' popular firewall product, FireWall-1. Although some people might question the allure of an appliance-based approach, anyone who has been under the gun supporting mission-critical firewalls when one of them decides to keel over will most likely jump on this bandwagon. The IP650 has several advantages over traditional firewall installations. The two that stand out are a simplistic approach to restoring failed units and a prehardened, as well as prepatched, operating system. It should be noted, however, that such benefits come at a price: Nokia releases recompiled versions of FireWall-1 only after official Check Point releases. This delay puts Nokia builds of FireWall-1 a little behind on the upgrade cycle, though in the past Nokia customers have been shielded from bugs Check Point has missed. Although the Nokia IP650 has been shipping for some time, it took us a while to get our hands on one. But as soon as I received the unit, I began its integration into our production network. Unfortunately, replacing the existing Cisco Systems PIX firewall proved to be a bit more challenging than I had anticipated, primarily because of some ambiguous documentation that shipped with the IP650. But I'm not sure I can blame Nokia for this one: It seems the entire computer industry has gone the route of cheap labor when it comes to accurate documentation efforts.
Voyager Takes Flight Fortunately, command-line junkies and paranoid administrators will take comfort in the fact that the IP650 does come with an ssh daemon, and you can use Lynx to access the Web interface over an encrypted ssh tunnel. This combination avoids the clear-text password issues, but isn't as aesthetically pleasing. After I completed the initial IPSO configuration, I moved on to the FireWall-1 configuration. This was fairly painless after I shredded the remaining traces of the Nokia-supplied documentation that had led me awry. Once the Check Point firewall module was installed and configured, I pushed a firewall rule set to the unit from my Check Point firewall management console, just as you would with any other Check Point FireWall-1 platform. The IP650 appears to integrate into existing Check Point environments seamlessly.
Fit and Trim Design Another plus is the fact that I could rebuild and reconfigure a firewall in about 20 minutes--the time it takes to restore the IPSO image and configuration files from the network. For anyone who has gone through the mind-numbing process of installing an operating system and then the 10 billion service packs, hot fixes or patches, the IP650's rebuild--simplicity in itself--comes as a welcome surprise. Upon hardware failure you simply slap in a replacement part, or even an entirely new IP650 unit, restore the IPSO image and the firewall rule set, and you're ready to go. The IP650 also boasts a wide range of interface types--everything from token ring to ATM to actual CSU/DSU and v.35 support. Nokia also claims to do some high-availability VPN (virtual private networking) support. With a Pentium II under the hood, a solid OS, and an industry-standard firewall package, the IP650 is a real workhorse. I think our Cisco PIX just "got lost." Greg Shipley is a Chicago-based consultant. Send your comments on this article to him at gshipley@neohapsis.com.
| |
Best of the Web
Data deduplication: Declawing the clones
Data deduplication is emerging as a critically important new arrow in the storage administrator's quiver to answer hard questions about the increasing problem in storage growth costs.
Compression, Encryption, Deduplication, and Replication: Strange Bedfellows
One of the great ironies of storage technology is the inverse relationship between efficiency and security: Adding performance or reducing storage requirements almost always results in reducing the confidentiality, integrity, or availability of a system.
WAN Optimization Whitelists and Blacklists
Optimization is a fantastic way of saving money and creating really happy customers at the same time, but it doesn't work flawlessly for all applications.
WAN Optimization as a Managed Service: It's Not About the Cost
This insight examines how organizations outsourcing their WAN optimization initiatives to a third-party go about achieving their goals for application performance, reducing operational costs, and streamlining enterprise infrastructure.






