All five reviewed products deliver impressive SSL VPN features
endif; ?>Connecting remotely to network servers is a fact of life for millions of end users. Whether working from a PC or a mobile device, users rely on secure, reliable remote connections to maintain their productivity.
We tested five products that deliver remote SSL/VPN connectivity: WatchGuard SSL 560, Barracuda SSL VPN 380, Dell SonicWall EX-7000, F5 Networks BIG-IP Edge Gateway 3900 Platform and Cisco’s ASA 5515-X security appliance.
We found each of these products to be capable, fully mature and established in the marketplace, which made it a bit of a challenge to choose a winner. Our top pick, the Cisco ASA 5515-X security appliance narrowly edged out the competition. While it didn’t dominate in every category, the Cisco ASA 5515-X won top billing due to its rich feature set, powerful and granular configuration options and overall balance of capacity and features.
The other four products were essentially all runners-up, each with unique features that make them suitable for implementation, depending upon individual remote connectivity requirements. The SonicWall EX-7000 and F5 Big-IP appliances are higher capacity units that can handle up to 5,000 and 60,000 concurrent users respectively.
The Barracuda SSL VPN 380 and WatchGuard SSL 560 fall more into the mid-range with the ability to handle concurrent users in the hundreds. Beyond capacity, which may narrow the field for organizations needing to support large numbers of users in a high throughput environment, choosing an SSL VPN solution is largely a matter of matching features to remote connectivity requirements.
The SonicWall EX-7000 maintained a slight edge in endpoint control and logging features; while the Barracuda SSL VPN 380 proved to be more capable in creating resources and displaying system status. Both products offer an efficient web admin interface that streamlines administration tasks.
The WatchGuard SSL 560 had a somewhat dated interface and lacked the ability to dynamically link to external directories, for example, Active Directory and LDAP. On the other hand, setup and deployment was a breeze with this unit compared to all the other products we tested. The WatchGuard SSL 560 is truly a ‘no fuss’ solution that is ready to roll right out of the box, very appealing for any shop needing to get up and running quickly.
The F5 has a lot of firepower and features, but we found configuration to be an arduous task compared to the competition. Configuring the F5 unit was time-consuming and sometimes cumbersome, even with the use of built-in wizards. On the plus side, the F5 appliance has an impressive client interface and excellent reporting capabilities. Did we mention mind-boggling capacity and throughput?
How we did it
We set out to test several scenarios; access to a remote LAN including file shares, remote desktop, internal Web resources and applications, as well as the basic mobile capabilities of each product. Some of the appliances tested were primarily SSL VPN solutions whereas others include additional features such as firewall, anti-virus and network accelerators, to name a few. Generally speaking, the more features, the steeper the learning curve, but this is only logical.
Our main focus was remote connectivity for end users. We were able to successfully create client connections to remote networks and network resources using the access methods provided with each product. Product differences came down to features, such as the granularity and flexibility of access control, together with administration capabilities and ease-of-use/deployment.
We did not evaluate performance as this involves too many parameters that can vary widely in production environments. However, we found performance acceptable and consistent across the products tested in our lab.
[ALSO: Java security questions answered]
Here are the individual reviews:
WatchGuard SSL 560
We hooked this unit up to a server via Ethernet ports and performed the basic set up in just a few minutes using the quick start guide. The Web admin interface is not the most sophisticated, but navigation is intuitive and relies on simple wizards to perform common tasks such as adding users and creating resource access rules.
Users are authenticated against a built-in database, as the WatchGuard SSL 560 does not have the ability to dynamically link to an external directory. However, you can use an external directory such as Active Directory, OpenLDAP or Novell eDirectory to create users or you can import a file containing user names. When linking to an external directory you will need to synchronize changes made to the external directory by using a refresh tool.
Using the aforementioned wizards we quickly and easily created users and configured network resources. Next we checked out the client interface. After logging in, the remote user is presented with a choice of authentication methods: SSL password, SSL challenge, mobile text, SSL Synchronized or SSL Web.
Resources can be accessed via tunnel or Web resource — the tunnel resource can be a full tunnel to a local network or one with more limited access, such as a home directory, file share or Outlook Client.
Examples of available Web resources are Microsoft SharePoint, Outlook Web Access, ActiveSync or any other internal Web resources such as a website. Once a type of resource has been selected, a built-in wizard can be used to configure the details and to set up rules to determine who has access to that resource.
We also tested access from an iOS device and found the mobile app easy to navigate with the up and down scroll only, as well as mobile-appropriate fonts and buttons.
This appliance does provide some endpoint control for Windows clients in ensuring that certain criteria are met before access is allowed. The WatchGuard SSL 560 doesn’t provide any built-in rules, but rules can be created to enforce access prerequisites, such as an application (e.g. anti-virus software), or for the existence of a registry key or file.
The reporting and logging capabilities of the WatchGuard SSL 560 are adequate with several built-in reports and some customization options such as date range and basic filtering. Reports can be exported to PDF and we discovered a useful ‘Complete Report’ that creates a PDF with nicely formatted data filtered by date/time.
The Web admin interface displays system overview information similar to the other products we tested, although not as well-organized or graphically appealing. On the plus side, the SSL 560 is a very easy system to manage, both from an admin standpoint and from the client standpoint. We referred to the context-sensitive help section only once or twice and, unlike our experience with a couple of other products, we did not need to contact technical support to clear hurdles.
Barracuda SSL VPN 380
The initial configuration of the Barracuda SSL VPN 380 can be completed directly from a console on the appliance or through a Web interface. We elected to use the console to initially configure the IP settings and then switched over to the Web admin interface. The appliance has a built-in user database which we used for testing, but the Barracuda SSL VPN 380 can also link dynamically to external user data directories such as LDAP, Open LDAP and Active Directory. The ability to utilize external user directories is important in production environments, especially those with large numbers of end users.
The Barracuda SSL VPN 380 Web admin interface has an appealing look and the status screen displays a number of useful parameters ranging from CPU fan speed and temperature to the number of users and session types. Most of the functionality is easy to locate using helpful tabs for each category.
There are also sub-tabs that quickly point you in the correct direction when configuring the appliance. Another handy feature is the messaging at the top of each screen that alerts users to items that need attention, such as unsaved settings. The same message area also alerts administrators each time an item is changed and saved.
As previously noted, users can be authenticated against a built-in database or an external directory. Creating user accounts is a straightforward process using a single-screen dialog with just a few parameters, such as user name, password and email address. You can also optionally assign users to groups.
After creating test users we configured several common network resources that could be remotely accessed from the client portal. The Barracuda SSL VPN 380 offers a number of choices for resource types, ranging from Web forwards and network places to applications and tunnel resources. Each resource can be configured from a single screen.
While wizards are always a nice touch for beginners, a single-screen configuration is an important feature for busy administrators. At the bottom of each configuration screen is a list of existing resources for that category. One change we would find helpful would be to color-code the active tabs in a way that would easily identify the task at hand, vs. shades of blue that were sometimes a bit confusing.
We created and configured several resources (SSL tunnel, RDP and a Web application) on the Barracuda SSL VPN 380 before switching to the Web client portal where, after logging in, our previously configured resources were displayed as icons. The client portal is basic with no frills, consisting of the login screen, a help section and the ability for the client to update some system information.
For mobile access, the Barracuda SSL VPN allows devices secure access to the network by using the VPN protocol native to the device (iOS, Android, Windows Mobile).
We found the logging capability of the Barracuda SSL VPN 380 to be adequate, but not as full-featured as some of the other products we tested. The Barracuda SSL VPN 380 does have a very good reporting module with the ability to add parameters and export capabilities to multiple formats such as PDF, XML, HTML and CSV.
The unit also ships with built-in endpoint controls that can validate against certain criteria before allowing the connection. Items that can be evaluated include OS and browser versions, anti-virus capability and whether an OS is up to date with all hot fixes (Windows only).
Dell SonicWall EX-7000
SonicWall was acquired by Dell in 2012, and Dell is now in the process of becoming a privately-held entity, but at least for now it appears the company is keeping the SonicWall name for this line of Internet appliances. Our test appliance was a Dell SonicWall EX-7000.
The initial setup of IP and DNS settings was done using the display and buttons found on the front of the appliance. After the initial setup, we connected the appliance to the test network and completed the remaining configuration tasks from the Web admin interface. The Aventail Management Console is efficient and easy to navigate, with the initial dashboard displaying key information in an easy to read format. We liked the checklist that shows any pending items needing attention with the ability to drill down for details.
There are three main client access methods available: Network tunnel client, Web proxy agent and client/server proxy agent. End users can connect remotely using methods such as a connect tunnel client, connect mobile client and on-demand tunnel agent.
However, the main access point is the Aventail WorkPlace portal, which provides access to Web-based resources. We especially liked the ability to customize the portal for different audiences, such as associates or customers. The Dell SonicWall EX-7000 supports the Mobile Connect client on iOS and Android devices, as well as most mobile browsers.
Users can be authenticated against network repositories such as Active Directory, LDAP and RADIUS, through a single sign-on server or using a local database. The SonicWall appliance uses ‘realms’ to tie together authentication, resource access, user management and endpoint control. This is visually displayed in flow chart-like display from the Admin interface, making it easy to see what is currently configured, with the option of managing each item from one location.
Similar to other appliances we tested, the Dell SonicWall EX-7000 uses rules for access control. We liked the way rules are enforced — once a client requests access, the rules are evaluated in order of precedence, and once a matching rule is found, the appropriate action is applied. If no matching rule is found, access is denied. Access rules are tied to available configured resources such as file shares, RDP access, applications, Web resources or host.
We found that the Dell SonicWall EX-7000 had robust end point configuration capabilities, allowing us to ensure that clients connecting to the network met our configuration prerequisites, such as operating system and anti-virus protection, or even more granular requirements such as matching equipment IDs or client certificates.
Although the SonicWall does not offer direct reporting from the admin interface, the logging features of the appliance are robust and they can be offloaded to a separate application called Aventail Advanced Reporting (AAR), which is built on the Sawmill log parsing/analysis application. The AAR allows administrators to drill down and query the logs to show specific user and application access information over any date/time range.
The admin interface is easy to navigate and setting up rules and resources is quick and intuitive. However one thing that was a minor irritation was that we kept forgetting to hit the (required) ‘pending changes’ link to apply our changes. The location of the link is not very intuitive – an ‘apply changes’ button as you make changes would be more helpful from a usability standpoint.
The Dell SonicWall EX-7000 was a very capable appliance with all the features needed to meet demanding remote connectivity requirements. However, it was hard to avoid noticing the $70,000 price tag on our appliance (configured with all the bells and whistles for 1,000 users with one year of high priority, 24/7 support).
F5 Networks BIG-IP Edge Gateway 3900 Platform
The F5 BIG-IP appliance can be configured either via command line or through a browser based Web admin system. To keep things somewhat consistent with our testing approach for the other appliances, we switched to the Web admin interface after assigning the initial IP address using the front end display and buttons. The admin interface is full-featured, but somewhat imposing for a first time user. We chalk this up to the additional capabilities of this appliance beyond SSL VPN.
Users can be authenticated using a variety of methods such as RADIUS, LDAP, Active Directory and Kerberos. Creating a link to an authentication server was straightforward using a single-screen configuration. The left navigation on the Admin interface is well-engineered, consisting of three tabs, one each for navigation, context sensitive help and about, with the about tab providing access to a variety of resources.
What we found a bit cumbersome with the F5 was making sure we had all the pre-requisites in place in order to create a client resource. However, after a bit of trial and error and with assistance from the help resource and technical support, we were finally able to create the access policies and a public interface from which clients could access the network.
The F5 BIG-IP client is available for Windows, Mac, and Linux in addition to Windows Mobile 5.0 or higher. For iOS and Android devices there are two different apps available, the Edge Portal and the Edge Client. The Edge Portal app provides access to internal Web apps such as intranets and Microsoft SharePoint, the Edge Client app offers the same capabilities with the addition of the ability to create an optimized SSL VPN tunnel to a corporate network.
We installed the Windows desktop version and were impressed with the ease of use and how quickly it allowed us to change our destination point from one server to another. Once connected to the VPN, we were able to access and utilize network resources such as file shares and applications. The client app displays useful information about connection details and compression ratios, which are used to speed up connections.
We especially liked the F5 reporting capabilities. These were the best of all the products tested and include a number of built-in reports, such as ACL summaries, browser distribution and various session reports, to name a few. There is also a report builder that can create custom reports using flexible parameters, operators and constraints. Another great feature is the modern looking dashboard that gives administrators a single-screen view showing multiple values, including the current status with a timeline of current and previous connections by type. Several of the values are displayed in speedometer-style gauges that are sure to appeal to administrators.
F5 Networks says the BIG-IP Edge Gateway 3900 acceleration feature allows remote connections 10x faster than without acceleration, supporting up to 600 logins per second and 600 concurrent users. While we didn’t independently verify these impressive-sounding numbers, acceleration sets the BIG-IP Edge Gateway 3900 apart from the other products we tested and may make this product especially appealing in demanding environments requiring very high throughput.
Cisco ASA 5515-X
Like the other appliances we tested, the ASA 5515-X from Cisco is a 1U rack mountable unit with administration options via browser-based or command-line interface. There is a lot to like about the Cisco ASDM interface, with the device dashboard providing a good status overview of parameters such as current VPN sessions, resources and traffic.
One big plus from an admin perspective was the context-sensitive help topics provided throughout as we were creating policies and configuring the appliance. One aspect of the help feature we found beneficial was the available links that allow you to navigate directly to the applicable area from which you can perform certain tasks. There are also a number of helpful wizards available to walk administrators through various tasks and we were able to take advantage of those in configuring the appliance.
The ASA is optimized for use with the Cisco AnyConnect client and although we performed a few client-less (browser only) connections, most of our testing was completed using the AnyConnect client from both stationary and mobile clients. The AnyConnect client is typically installed from a browser session to the ASA or it can be manually installed on the client or using various login scripts.
In addition to running on most desktop operating systems, AnyConnect is available for mobile on iOS and Android, and according to Cisco it will be available for Windows Mobile soon. Data can be protected by using either a SSL or IPSec tunnel, however, the SSL tunnel is only available when using the AnyConnect client.
Authentication can be accomplished against one or more external directories or using a built-in database. Setting up local users is quick through a wizard-like interface that allows you to go with the basics or expand into more advanced settings. All connections are made using client and connection profiles, which can also inherit settings from group policies. This provides for great granularity in how access is provisioned, but can be time-consuming when configuring the unit for the first time.
That being said, many settings use defaults that most users would probably use, and the built-in wizards are a great resource if you need to get something up and running quickly. This is how we created our first few policies and got up and running in a few minutes.
Similar to the other products we tested, the Dynamic Access Policy feature allows administrators to validate end point criteria before access is granted. We especially liked the ability to test a dynamic access policy on the fly before saving it.
Once the client is installed, it can be accessed from a shortcut on the desktop or from a browser window. The client software is available for most operating systems and we tested it both on Windows 7 and an iOS mobile device without any issues.
The logging and reporting capabilities of the ASDM software are very good and the real-time access to the SysLog affords administrators the ability closely observe traffic patterns and take corrective measures as needed. We would not recommend this appliance to newbies, but accomplished system administrators looking for raw power and the ultimate control over remote connections will definitely want to consider the Cisco ASA 5515-X security appliance.
Perschke is CSO for Arc Seven Technology. She is also an experienced technical writer, and has written numerous white papers for a number of organizations, including Fortune 500 companies. Susan can be reached at susan@arcseven.com.




