home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Security
S N E A K   P R E V I E W  
FortiGate Fortifies Your Traffic Security

  August 5, 2002
  By Mike DeMaria


TOC Issue TOC
Printer Print full article
E-Mail E-Mail this URL
flameauthor Flame the author

The sea of firewall and VPN appliances flooding today's market couldn't discourage Fortinet from introducing its FortiGate 500 Network Protection Gateway--and that's good news. The product's standout features include the ability to set up multiple security zones and handle routing, content filtering, traffic shaping and failover. I tested a beta version of FortiGate 500 in our Syracuse University labs and appreciated its ability to manage, inspect and route traffic between multiple subnets. However, Fortinet needs to update the management interface to reflect the product's new capabilities.


FortiGate 500 sits on the edge of the network behind the Internet router. In addition to having an external, an internal and a DMZ interface, the appliance has eight more 10/100 Fast Ethernet ports. Management is done from a GUI through an SSL Web connection or through SSH (Secure Shell).

Each FortiGate port houses a separate subnet; the device can route packets directly from one port to another or perform many-to-one NAPT (Network Address Port Translation) between ports. Individual ports can be assigned to unique security zones or can be grouped into a shared security zone. Each security zone gets its own separate policy, which means you can group multiple subnets into a zone and set access rights between zones. If two ports are in the same security zone, you can block traffic from flowing between them.

Access Control

To set up the firewall controls between zones, you first need to define traffic flows. From the GUI, I designated flows between internal and external zones, and Zone 1 and the external zone. You can also indicate if these flows should be routed or sent via NAPT. Traffic between interfaces within the same security zone can be blocked or routed as well. After setting flows, you can create policies for each zone.

Good News
  • Controls access between subnets.
  • relatively simple to use.
  • Multiport routing capabilities.
  • High availability support.

    Bad News
  • management interface needs redesign.
  • Gui Needs to Better Reflect Multiport capabilities.
  • Limited Network IDS support.

  • When entering the policy management interface, you are presented with two drop-down menus, one for source zone and one for destination. You need to select which zones to use for each before you can edit policies for a flow. Each security zone may contain several subnets, and the firewall policy will let you select if you want to apply a rule only to one network or to a group of networks inside a zone instead of to the entire zone. My only problem with this is that the management interface still seems geared toward the three-port FortiGate products. However, when you have multiple security zones, seeing all the interactions and rules between ports is difficult.

    At this point, I set up traffic-shaping controls for guaranteed and maximum bandwidth in each policy by queuing packets, as opposed to manipulating TCP window size. I enabled a policy stating that HTTP traffic cannot exceed 30 KBps, and my Web downloads dropped from 250 KBps to approximately 29 KBps per download. You can also create schedules for when the policy will be in effect.

    The antivirus capabilities work well, but I've seen better. FortiGate 500 presents identical configuration options for HTTP, SMTP, POP3 and IMAP for IDS, virus scanning and file blocking. Fortinet uses its own virus definition file and provides updates as new signatures are found. To define antivirus policies on your own, you need to select a flow to monitor--you cannot specify a global policy to monitor all traffic across all zones. At this point, you can choose to scan for viruses or to block files based on any of 12 file extensions. Unfortunately, these are not configurable. The inspection software can look inside compressed files but does not recursively check them within the archive. To my disappointment, when I changed the extension of an executable to .jpg, the file was transferred without its being caught. Fortunately, virus scanning, as opposed to blocking, will catch files regardless of the extension.


    Vendor Information
    Network Protection Gateway, $9,995. Available: August 15. Fortinet, (408) 235-7700; fax (408) 235-7737.
    www.fortinet.com

    VPN and Content Filtering

    The device supports both client/server and site-to-site VPN access. Client/server access is performed with PPTP (Point-to-Point Tunneling Protocol) or IPsec using the Safenet client. Sessions terminate in the internal zone, so you can't have a user connect through a VPN directly into the DMZ or any of the other security zones. The user's access rights follow those of the internal zone. You can add users manually or through a RADIUS server. Site-to-site access is through IPsec, and DES, 3DES, MD5 and SHA1 are all supported. You can use only preshared secret keys. I ran into interoperability problems in our site-to-site tests with Cisco Systems' 3005 Concentrator and Nortel Networks' Contivity. Fortinet claims the beta bugs that caused the problems will be cleared up before the product's release.

    Content filtering is simple and uses URL blocking enhanced by a rudimentary user-generated banned-word list. URL blocking supports unicode URLs, and a list of predefined URLs is provided, but you can import other lists or add your own. The script filter will let you choose to block Java applets, ActiveX or cookies. A deal with Secure Computing integrates SmartFilter into the FortiGate 500. Unfortunately, this wasn't announced until after our tests.

    The device I examined did not contain a hard drive, so there were no built-in logging capabilities, but Fortinet gives you the option of adding a 20-GB internal hard drive to the appliance for $499. The product would work well as an access control device in smaller networks with multiple subnets to protect. Controlling traffic between subnets with Fortigate 500 doesn't require much skill, but it can get more confusing as the number of networks increase.

    Michael J. DeMaria is an associate technology editor based at Network Computing's Syracuse University's Real-World Labs®. Send your comments on this article to him at mdemaria@nwc.com.









    Looking for a new job?

    Function:

    Keyword(s):

    State:
    SPONSOR
    RECENT JOB POSTINGS
    CAREER NEWS
    The tumbling of IT jobs stopped in the second quarter, as the IT sector added about 44,000 jobs.

    It's just a glimmer, but Oracle is starting to see a bit of light at the end of the recession tunnel.










    2009 IT Salary Survey: Meager Raises, Solid Prospects
    Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
     
    ROLLING RIGHT ALONG
    Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



    Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








    TechSearch


    Microsite of the Week


    Powerful Information at Your Fingertips



    Techweb
    Informationweek Business Technology Network
    InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
    Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
    Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
    space
    TechWeb Events Network
    InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
    Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
    space
    Light Reading Communications Network
    Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
    Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
    space
    Financial Technology Network
    Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
    space
    Microsoft Technology Network
    MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
    space


    App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
    About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
    Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service