Check Point's VPN-1 Edge W security device picks up wireless support

By Joel Snyder
Network World, 05/30/05

Original Article on Network World Web Site

Check Point's new VPN-1 Edge W touts wireless access support, better performance and a new print server, a combination that makes it a solid addition to the company's line of small security gateways. In this exclusive Clear Choice test, we focused on the features most attractive to enterprise network managers: wireless, VPN, QoS, high availability and management.

The Edge W - anchored with a scaled-down version of NG Version 5, Check Point's enterprise-class firewall - ships with six Ethernet ports, two wireless antennas and a serial port that can be used for console access or dial backup. One Ethernet port is dedicated for Internet outbound access, with the others assigned to other functions. The Edge W can support up to seven security and IP routing zones, or as many as 10 zones if you use 802.1q virtual LAN tagging.

The most obvious addition to the Edge W is wireless support in the form of an embedded 802.11b/g access point with optional "Super G" mode (a derivative of the 54M bit/sec 802.11g standard that bonds channels together for higher throughput). Although the Edge W has solid security applied to the wireless network, with 802.1X, Wi-Fi Protected Access Personal (pre-shared key authentication) and WPA Enterprise (802.1X authentication) included, Check Point didn't go all-out on the wireless feature set. For example, the wireless connection cannot be used as an Internet up-link, and only a single Service Set Identifier and security zone is supported for wireless users. Advanced Encryption Standard encryption is not there yet.

While the Edge W's wireless security capabilities aren't impressive, what is included in the box works fine. We tested WPA Personal and WPA Enterprise features and had no problems connecting with Windows and Mac clients, or with our Funk Odyssey RADIUS server for 802.1X authentication (see How we did it at www.networkworld.com, DocFinder: 7322 ).

For basic configurations, a Web browser is sufficient to take the Edge W from "out of the box" to running the firewall within a few minutes. It's easy to jump into advanced configuration and define rules that control traffic flow, network address translation and QoS shaping in a simple and unified way. The Edge W also has a command line interface via the console port or a network connection.

For large deployments, Check Point offers SmartCenter, a centralized management system that can control and push unified firewall policy down to multiple Edge W devices. We connected to Check Point's Service Center to receive firmware, content filtering and virus signature updates. SmartCenter provides the ability to manage the configuration of hundreds or thousands of Edge devices using current management tools.

QoS has become a hot topic with the rise of VoIP, and while the buzzword is used to describe the Edge W, it doesn't have all the technology in place yet. Check Point's QoS capabilities include packet tagging and bandwidth management. While it was easy to set aside bandwidth for the IP addresses occupied by our Session Initiation Protocol (SIP )-based IP telephones, the test results showed that the Edge W doesn't have a very sophisticated technology for QoS management. To that end, the tests in which we attempted to share a DSL line with both SIP-based VoIP traffic and a heavy download of Microsoft service packs were not very successful. In the upstream direction, the Edge W was able to guarantee a solid 64K bit/sec of bandwidth for our voice call, with excellent quality. Without any real management in the downstream direction, the received voice quality was poor, with numerous dropouts as VoIP packets arrived late or with too much jitter.

The VPN capabilities on the Edge W let you use it to easily and quickly join a Check Point VPN. We tested this with a Check Point NG firewall and were able to bring up a tunnel within a few seconds. An elegant feature of Check Point's overall VPN architecture is the dynamic pushing of network configuration, meaning that the Edge W doesn't have to be configured to know anything about the central VPN server besides its IP address and how to authenticate.

VPN-1 Edge W OVERALL RATING
4.0
Company: Check Point Cost: Ranges from $800 to $2,200. Pros: Great VPN remote access capa-bilities; good integration with other Check Point VPN devices; VLAN and multi-zone support; multiple management options. Cons: Uplink capabilities using wireless or DSL not available; NAT configuration difficult to manage in advanced topologies; advanced wireless security technologies are not yet supported; poor third-party VPN interoperability.
The breakdown   
Basic firewalling 20% 4.5
QoS and threat
management capabilities 20%
3
Manageability 20% 4.5
VPN and advanced security features 20%
4.5
Wireless capabilities 20% 3.5
TOTAL SCORE  4.0
Scoring Key: 5: Exceptional; 4: Very good; 3: Average; 2: Below average; 1: Consistently subpar

 

The Edge W also includes a VPN tunnel server for remote access, relying on Check Point's current Windows and Mac clients to make the connection. The Edge W also includes an "internal" VPN server that you can use to require internal users to authenticate and encrypt before they're allowed out of the network. This is moderately useful in the wired case, but also has relevance with wireless connections, where it can be used as an alternative to WPA security. This will be most interesting in environments where the Check Point client already is installed and people are using it for remote access.
The Edge W includes threat management tools such as virus scanning and URL filtering, but is limited in its capabilities. For example, only SMTP and Post Office Protocol traffic are scanned for viruses, while IMAP and Webmail are not scanned.

Check Point has pushed down into the Edge W a number of high-availability features available in its larger firewalls. The Edge W offers WAN failover capabilities based on the existence of a second Ethernet port that can be dedicated to managing a second upstream Internet connection. The Edge W also has support for device high availability, with state sharing across two cooperating devices.

After using the Edge W as a production firewall for a week, the verdict is "solid, but uninspiring." The Edge W will be most useful in VPN-oriented environments, including both site-to-site and remote access - taking advantage of Check Point's heavy expertise there. But we don't recommend you buy it solely to pick up wireless firewall capabilities.