Netgear ProSafe Wireless N SSL VPN Firewall in Security appliances
Verdict
Netgear offers a clever combination of IPSec and SSL VPNs along with wireless-N services and all at a very reasonable price.
Review Date: 17 Apr 2009
Price when reviewed: £253 (£291 inc VAT)
Overall Rating

Features & Design

Value for Money

Performance


Netgear's latest SMB router brings together a veritable cornucopia of features as it combines firewall duties, IPSec and SSL VPNs plus traffic management, and melds them together with a dual-band wireless-N access point. Supporting both VPN types simultaneously allows it to manage encrypted site-to-site tunnels and secure remote access for mobile workers at the same time.
The SRXN3205 has a quartet of Gigabit LAN ports and a single RJ45 WAN port that can be used for a direct connection or adding a suitable DSL or cable modem. The three removable wireless aerials are fitted at the back and the access point supports 802.11n/g or n/a operations, but not both together.
Netgear's web interface is well designed and provides easy access to all features. The SPI firewall defaults to blocking all unsolicited inbound traffic, but you can modify it with your own rules.
Specific services can be blocked or allowed and one of three time schedules applied. With only a single WAN port, failover is not an option, but traffic metering will prove useful as limits in MB can be applied to WAN usage.
If usage is exceeded during the current month all further access can be blocked. The counter can be reset on a specific day of each month, you can allow a temporary increase if the threshold is breached and also let email through if required.
Web browsing restrictions can also be applied although these are nothing more than URL or keyword lists.
LAN systems are placed in one of eight groups and have URL keyword blocking applied to them. You can only create a single URL keyword list and apply it to selected groups, so it's not possible to use different policies for each group. Wireless security includes WPA/WPA2 and RADIUS authentication plus ACLs using client MAC addresses. For wireless-N operations both 20MHz channels can be enabled and you can choose either 802.11a or g, as accompaniment.
For SSL VPNs the router supports multiple authentication domains which determine what LAN resources your mobile clients are allowed to access. Features are quite basic, as you can only define LAN resources based on IP addresses and port combinations. If you want application proxies then check out dedicated appliances such as Billion's BiGuard S20 or Netgear's own SSL312.
VPN tunnels provide full remote access to the LAN as though the client were locally connected. The port forwarding mode allows you to restrict access to specific servers and services, although this only supports TCP. Once a remote user logs on to the appliance they are redirected to a portal page that can be customised to suit.
Selecting the connection icon loads an ActiveX control that creates a virtual network adapter with an IP address assigned from a pool on the appliance, and we were able to create policies that restricted remote access to our internal FTP, web and mail servers. Performance isn't great, though, as the Netperf utility reported an average link speed between client and server of less than 2MB/sec.
There are some compromises in terms of features but having SSL and IPsec VPNs plus wireless-N services in a single box makes the SRXN3025 quite unique. It's easy enough to use and SMBs will like the low price tag as well.
Author: Dave Mitchell
advertisement
- Web censorship "breaches WTO rules"
- Facebook users to join the IM crowd
- Government promises broadband windfall for Scots
- Kingston bringing films to a flash drive near you
- Scientists tout cloaking tool for search engines
- Six-pack of fixes set for Patch Tuesday
- British Legion calls for Twitter silence on Poppy Day
- Spotify stems interest in illegal downloads
- Postal strike leads businesses to online alternatives
- Microsoft wants to expand Yahoo deal worldwide
- Motorola pays Lucas for its Droid
- Where are the killer apps for Windows?
- Will you hit the Orange iPhone "unlimited" cap?
- USB 3 first benchmark - it's here, and it's fast
- Why Windows 7 has forced me to worry about security
- How Dixons is (under)selling Windows 7
- Do I like Windows 7 because it's so like a Mac?
- No Windows 7 drivers turn Dell M1330 into a doorstop
- Is Windows 7 good looking enough to sway an Apple fan?
- Typekit brings print-like typography to the web
- When will you get superfast broadband?
- The Crapware Con
- The 10 greatest tech U-turns
- Windows 7: everything you need to know
- PC 2010 and beyond
- The High Street Rip Off
- How to avoid the high-street rip-offs
- Do online protests really work?
- How to buy Windows 7 for £50 less: the truth about OEM versions
- Free computing lessons for kids
- The bulletproof Dell that costs an arm and a leg
- Microsoft Office 2010 Technical Preview: Q&A
- Lawnmowers, the TyTN II and one odd insurance request
- There'll never be a bulletproof OS
- How far can we trust apps?
- Five nice touches in Outlook 2010
- Building a better Google
- Beware HP's horrendous printer-driver glitch
- Microsoft debuts free Morro antivirus package
- Getting started with Search Server 2008 Express
advertisement

Printed from www.pcpro.co.uk

