Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up
Security
R E V I E W  
Defense Starts Here

  February 20, 2003
  By Mike DeMaria


>> continued from previous page

Sygate Secure Enterprise 3.0
TOC Issue TOC
Printer Print full article
Printer Print this page
Printer Download as PDF
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
Measuring Protection
arrow
Sygate Secure Enterprise 3.0
arrow
Other Products Reviewed
arrow
Executive Summary
arrow
Beyond the Initial Expense
arrow
The Layering Effect
arrow
Report Card

Sygate's package--comprised of Sygate Management Server (SMS) and Sygate Security Server--offers the best blend of protection, management and integration. Its support for multiple administrators and policy inheritance and its compatibility with antivirus and VPN products helped this firewall win our Editor's Choice award.

Sygate's Java management-configuration tool uses an inheritance structure in which global security policies apply to all users and groups. Once you've established the global policy, you can create subpolicies that override or supplement it. You can also nest multiple subgroups. For example, we created a global policy to allow Internet Explorer for all users. We then created a "tech editors" subgroup with FTP access. Changes in the parent policy take effect on all the subgroups below it. If we added a rule to allow SSH (Secure Shell) in global, the tech editors would have gotten access to SSH. Users can be assigned and moved around any of the groups or subgroups.

SMS lets you create multiple administrators and give them tasks, adding to the product's flexibility. To test this feature, we created groups called CMP East, CMP West and NWC Syracuse, then assigned one administrator account to each group. The NWC Syracuse admin could manage all his or her users based on his or her network's security policy, without seeing or affecting the other two groups. Besides SMS, only ISS's RealSecure package gets as granular.


SMS lets you configure rules to enable or disable DHCP, DNS, NetBIOS, OS masquerading and shunning attackers. The process is simple. When we ran an NMAP probe with OS masquerading enabled, for example, the software identified the system as a Red Hat Linux station to trick attackers into trying Linux attacks against a Windows workstation. This feature will mislead script kiddies performing scans for hosts, but it won't guarantee complete security.

The server software provides two methods for establishing trusted applications: manual input or client-learned. Every time a client with a learning-enabled policy launches a new Internet program, it reports the file name, version number and MD5 hash to the server. You can then add the appropriate applications to the trusted list. In test environments, new applications can be added to the approved application list automatically, or the management server can send you an e-mail when a user runs a previously undiscovered application.

Application discovery is important in the initial configuration and testing phases of deployment. We had one big complaint about the way the product accomplishes this. The server cannot dictate the components' MD5 hashes. Instead, these hashes are computed on the end node. Although this technique makes diverse environments easier to administer, it also necessitates installation on clean systems. If you install the firewall on a system that's already compromised, the firewall won't catch the Trojan. You can, however, dictate and require the executable's hash to come from the server. In other words, you can require iexplore.exe to have a certain MD5 hash, but the system DLL hashes cannot be centrally defined. Integrated antivirus and intrusion-detection support should catch any stragglers.

Sygate's is also the only product that lets you create multiple policies based on the user's location or tasks. For example, you can have one policy for local users, another for those connecting via VPN, and a third policy for wireless users. You can set policies based on MAC (Media Access Control) addresses, IP addresses, network adapters, VPN adapters, applications and time of day.

Sygate's report generation isn't as robust as ISS's: You can't drill too deeply into Sygate's graphs. Each rule, for example, can be assigned a severity on a scale from zero to 15. We created a rule that said running telnet.exe would produce a critical flag. After executing telnet on a client machine, we sorted the security log by severity. Our telnet violation appeared at the top. You can create line, bar and pie charts showing IPs, protocols, time, application or severity of attacks, but you can't take the reporting much further.

Sygate Secure Enterprise 3.0, starts at $30 per seat. Sygate Technologies, (866) 308-8899. www.sygate.com


start top  Measuring Protection Other Products Reviewed 

Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers