SmoothWall SmoothGuard 1000-UTM review
A wide range of security features for the price, but it isn't the easiest to configure and web-content filtering is poor.
Review Date: 19 Sep 2007
Reviewed By: Dave Mitchell
Price when reviewed: exc VAT; inc 1yr subscription for 250 users
SmoothWall has finally succumbed to the allure of the appliance. Its software has always offered a cost-effective firewalling solution, as it allows you to choose the hardware yourself. However, so many new components have been introduced to the base product, such as content filtering, antivirus and antispam, that it makes sense to offer them all in one box.
Some appliance vendors think they can get away with a cheap hardware platform, but the SmoothGuard 1000-UTM is a solidly built rack chassis with a decent processor, plenty of memory and seven Gigabit Ethernet ports. The web interface is easy on the eye, but it wasn't immediately obvious where some of the features are accessed from. Fortunately, installation is simple, as we defined the first port for our LAN with internal DHCP services and the second as our WAN connection with a fixed IP address.
The network ports can take on a range of roles so, as with Fortinet's FortiGate-224B, you can have internet access policies but also intrazone policies. By default, all zones are hidden from each other and you create bridging rules to allow specific zones to access others. For web filtering, the appliance can work in transparent and non-transparent modes, but in either case you'll need to configure client systems to use the appliance as a proxy. Non-transparent mode is the most versatile, as it brings in user authentication and allows extensive rules-based access policies to be applied to different users and groups. There are plenty of authentication modes to choose from, including the local user database or RADIUS, AD and LDAP servers.
The appliance uses a lot of open-source components, with ClamAV looking after web and email antivirus scanning and offering automatic updates as often as every hour. If you're not happy with this, you can use the ICAP server redirection feature and choose your own antivirus solution. Snort handles IDS functions and you can activate different rules and look only for particular attacks. The SmoothGuardian component provides web-content filtering and offers 53 URL categories to choose from. SmoothWall scores higher than many, as it also offers phrase checking within web-page content. Mailshell provides POP3 and SMTP antispam measures and is simple to use. It offers a range of RBLs, plus options to control attachment file sizes and scan messages for viruses.
Unfortunately, the URL filtering didn't impress, as with the games category blocked we tried to access 40 online bingo sites and were blocked from only 18. We used the same URLs with Websense Express and were blocked from 36 sites. Antispam performance was much better, as a four-day live test using the default sensitivity settings saw more than 90% of spam caught, with few false-positives.
For the price, SmoothWall offers a lot of security functions integrated into a well-specified hardware platform. Reporting and antispam are good, but configuration isn't easy and the content-filtering component could do better.
Author: Dave Mitchell
- Nokia Lumia 2520 tablet sales halted over faulty charger
- Microsoft slashes custom XP support price
- Amazon Phone: does anyone want a 3D handset?
- Virgin email fiasco hits thousands of users
- Chrome Remote Desktop now available on Android
- Google posts "average quarter" with slow growth
- What's on this week's PC Pro podcast?
- BBC iPlayer lets Android devices download shows
- Google's Project Ara modular phone arrives in January
- Hackers harvest LaCie card data for a full year
- Windows 8.1 Update: an abject surrender
- The insane economics of Sky Now TV
- No such thing as a free app... so pay up if you want quality
- Time to outlaw crapware-laden installers
- Windows Phone 8.1 video: hands-on
- Office for iPad: key information
- Why every PC buyer owes Richard Durkin a debt of gratitude
- HTC One M8 vs Samsung Galaxy S5: 2014's big-hitters compared
- Windows XP end of life: key information
- Cut out the broadband jargon? What jargon?
- The great iPhone ripoff and how it works
- Heartbleed: what you need to know and do
- Data recovery: inside the clean room
- Best tablet PCs to buy in 2014
- How much RAM do you really need?
- News of the weird: the strangest ever tech stories
- Five hyped technologies: disruptive or not?
- Piracy's dying: why we're all going straight
- Office: should you buy it, rent it - or dump it?
- Make the most of your mobile data
- Make your mobile battery last longer
- Small steps into handling Big Data
- Nexus 5: does it really run stock Android?
- How to get broadband to a garden office
- How to write your company's IT security policy
- Raspberry Pi and Wolfram: a must-have for every child
- Could you get by with Office Web Apps?
- The best Android antivirus apps for 2014
- Headings vs headers: how to use both in Word
- Windows Server 2012 R2: how the Datacenter edition could change SMBs