* The Reviewmeister tests out products that claim to protect network endpoints
Because setting up and deploying software that touches every client on your corporate network is no trivial matter, we assessed how each vendor handled this daunting process.
Because setting up and deploying software that touches every client on your corporate network is no trivial matter, we assessed how each vendor handled this daunting process.
For Zone Labs’ Integrity 5.0, which is now part of Check Point, we ran the installer, followed the instructions and were up and running in just a few minutes. Client deployments are available through a download link, but they also can be pushed out via any other deployment mechanism used in the company, such as Microsoft’s Group Policy setting or System Management Server.
Check Point provided the best documentation that was clearly written, detailed, accurate and easy to understand.
From our perspective, the most important component of these products is policy configuration, which is where you define how this product will protect your endpoint devices. With a poorly defined policy, you easily can prohibit valid communications or applications required to perform day-to-day business tasks or let malicious traffic/applications access your systems.
To test policy functionality, we attempted to create and deploy a policy that would block all inbound traffic except remote desktop, block outbound traffic to Port 23 on remote systems, block Netcat from binding to Port 468, and block Solitaire (sol.exe) from running. Once the policy should have been deployed, we tested remote desktop connectivity, telnet connections and our ability to play Solitaire. By trying to control these four processes, we can gain a good understanding the for parameters around which you can use these products to set policy across a broader set of application and network activities.
In our tests, Check Point was successful at blocking Port 23 outbound. We then configured each policy to allow inbound Port 3389 for Microsoft’s Remote Desktop Connection. Check Point successfully allowed the remote connection.
Check Point includes a reporting section, but it generally is just providing query results from the logs. We would like to be able to create graphs and summary reports, and export to PDF or another format. Print views are available in HTML, but they only show the query results displayed onscreen, not all of the results. We also would like to see options for custom reports and the ability to generate reports from the client status monitor information.
For the full report, go to https://www.nwfusion.com/reviews/2004/0920rev.html




