Netgear FVS336G
Verdict
Netgear delivers an affordable security appliance with the best of both VPN worlds and plenty more besides.
Review Date: 2 Jun 2008
Price when reviewed: exc VAT
Overall Rating

Netgear delivers an affordable security appliance with the best of both VPN worlds and plenty more besides
The full name of Netgear's latest SMB router says it all, as the ProSafe Dual WAN Gigabit Firewall with SSL and IPSEC VPN really does pack in the features. With both IPsec and SSL VPNs on the menu you can create secure site-to-site tunnels using the former, and for easy mobile access use SSL VPNs that only require the user to log in from a standard web browser.
However, the level of SSL VPN features aren't as good as those offered by the PC Pro Recommended Netgear SSL312, although considering this solution costs over £60 more it's hardly surprising. Instead of application proxies, you have a more basic set of controls where you define only LAN resources based on IP addresses and port combinations. You don't get the Network Places option either, but you can use different domains to authenticate users with the appliance's local database or via AD, NT domain or RADIUS servers.
Users can be offered VPN tunnels or port forwarding, where the latter uses a lighter ActiveX client but only supports TCP. For testing, we used one port connected to our LAN and the primary WAN port configured in a different subnet, with a collection of workstations behind it acting as remote clients. After logging on to the appliance, our users were redirected to a portal page with a connection icon. Selecting this loads an ActiveX control, which creates a virtual network adapter that's assigned an IP address from the pool on the appliance.
We had no problems creating different access policies, where we could decide to allow external access to our FTP and mail servers but stop anything else on the LAN being seen. Performance isn't particularly good, as copying a 690MB video clip from an FTP server on the LAN to a remote client saw average speeds of only 1.4MB/sec.
The SPI firewall defaults to blocking all unsolicited inbound traffic, but you can modify it with your own rules. Specific traffic can be blocked or allowed, and one of three schedules can be applied to determine when rules are active. Failover options are good, as you can set the second WAN port to act as a backup link if the primary link goes down, or bind both together in a single load balanced link. Traffic metering could also prove useful, as you can apply a limit in megabytes to WAN usage and if it exceeds this during the current month, all further access can be blocked. The counter can be reset on a specific day of each month, you can allow a temporary increase if the threshold is breached, and also choose to only let email continue if required.
Internet access controls can also be applied, although these are rather basic. LAN systems can be placed in one of eight groups and have URL keyword blocking applied to them. You can create only a single URL keyword list and apply it to selected groups, so it isn't possible to use different policies for each group.
The FVS336G is offering a very good deal to small businesses that want a good combination of network security features. The SSL VPNs aren't the best, but they work - and that Netgear has managed to include them at all at this price is quite remarkable.
Author: Dave Mitchell
advertisement
- Nokia recalls 14 million faulty chargers
- Play.com order glitch leaks names and addresses
- Rupert Murdoch considers Google block
- Skype safe as eBay strikes deal
- Rick Astley worm infects iPhones
- Web censorship "breaches WTO rules"
- Facebook users to join the IM crowd
- Government promises broadband windfall for Scots
- Kingston bringing films to a flash drive near you
- Scientists tout cloaking tool for search engines
- Motorola pays Lucas for its Droid
- Where are the killer apps for Windows?
- Will you hit the Orange iPhone "unlimited" cap?
- USB 3 first benchmark - it's here, and it's fast
- Why Windows 7 has forced me to worry about security
- How Dixons is (under)selling Windows 7
- Do I like Windows 7 because it's so like a Mac?
- No Windows 7 drivers turn Dell M1330 into a doorstop
- Is Windows 7 good looking enough to sway an Apple fan?
- Typekit brings print-like typography to the web
- When will you get superfast broadband?
- The Crapware Con
- The 10 greatest tech U-turns
- Windows 7: everything you need to know
- PC 2010 and beyond
- The High Street Rip Off
- How to avoid the high-street rip-offs
- Do online protests really work?
- How to buy Windows 7 for £50 less: the truth about OEM versions
- Free computing lessons for kids
- The bulletproof Dell that costs an arm and a leg
- Microsoft Office 2010 Technical Preview: Q&A
- Lawnmowers, the TyTN II and one odd insurance request
- There'll never be a bulletproof OS
- How far can we trust apps?
- Five nice touches in Outlook 2010
- Building a better Google
- Beware HP's horrendous printer-driver glitch
- Microsoft debuts free Morro antivirus package
- Getting started with Search Server 2008 Express
advertisement

Printed from www.pcpro.co.uk

