Skip Links

Network World

  • Social Web 
  • Email 
  • Close
Clear Choice Test Unified Threat Management Firewalls. All-in-one firewalls show spotty performance: Juniper, Cisco, Check Point lead the way in test of 13 unified threat management devices.
Intro to UTM Testing Testing categories Product Summaries Click tabs to expand

UTMs require routing for flexibility’s sake

By Joel Snyder , Network World , 11/12/2007

Dynamic routing is the kind of feature required of any UTM firewall as a means of providing deployment flexibility.

We tested the OSPF-routing capabilities of the UTM devices in order to simulate the kind of multiple-exit network (two Internet gateways) that might be common in a large network.

However, we do need to note that dynamic routing might also be useful on the inside of a multiple-zone firewall for a growing network as it picks up new subnets around the globe. VPNs, likewise, are perfect places for dynamic routing to be used. As a large VPN grows, the burden of managing the list of networks at each point in the VPN can be high, and dynamic routing combined with VPNs can help to maintain reachability information on what networks are connected without making every single device reconfigure its VPN each time the network changes. When VPNs are combined with dynamic routing, a tight integration among firewall policy, VPN rules and dynamic routing is required.

Tracking UTM firewall routing support

Vendor Product Unicast protocols supported Multicast Routing supported
Astaro ASG 425a OSPF N
Check Point UTM-1 2050 BGP, OSPF, RIP Y
Cisco ASA5540 with SSM-20 IPS module OSPF, RIP (EIGRP in v8) Y
Crossbeam C25 BGP, OSPF, RIP Y
Fortinet FortiGate 3600A BGP, OSPF, RIP Y
IBM System x3650 BGP, OSPF, RIP Y
IBM/ISS Proventia MX5010 OSPF N
Juniper Networks ISG-1000 BGP, OSPF, RIP Y
Juniper Networks SSG-520M BGP, OSPF, RIP Y
Nokia IP290 BGP, IGRP, OSPF, RIP Y
Secure Computing Sidewinder 2150D with IPS accel. BGP, OSPF, RIP N
SonicWall PRO 5060 OSPF, RIP N
WatchGuard Firebox Peak X8500e BGP, OSPF, RIP N
Click to see: Tracking UTM Firewall routing support

Two vendors stood out for making dynamic routing especially easy: Juniper, in both the ISG-1000 and the SSG-520, and Nokia, in the IP290 with Nokia’s IPSO operating system and Check Point’s VPN-1 firewall. While Juniper doesn’t offer the full suite of routing capabilities available on its enterprise and carrier-class routers, the ScreenOS routing features in combination with its virtual routers within the firewall and easily manageable configurations will probably go way beyond what is needed in most UTM environments. Likewise, Nokia’s IPSO platform has long had a very strong routing base, that supports clustering and a broad range of protocols .

To stress the extended features in both Juniper and Nokia dynamic routing, we also added a Border Gateway Protocol session to our test devices and made sure that we could control the propagation of routes between OSPF and BGP.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comments (2)
Login
Forgot your account info?

RE: Cisco UTMBy Joel Snyder on November 17, 2007, 9:03 pmWell, a better question is: "what is in the PIX/ASA for dynamic routing?" The answer is "not very much." Cisco's current design for the ASA is not going into...

Reply | Read entire comment

RE: UTMs require routing for flexibility's sakeBy tom on November 15, 2007, 1:43 pmwhat was missing in cisco utm for routing support?

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

what are the benefits of project management - Anonymous

Join the Discussion