Home > Midmarket IT Security Security Schools > Midmarket Security School > Securing your first remote office: Solutions for less than $10,000 > How to set up a UTM firewall to secure a remote office
Security Schools: Midmarket Security School:
EMAIL THIS
 START   IAM   INTELLIGENT THREAT MANAGEMENT   NETWORK INFRASTRUCTURE SECURITY   VISTA   PERIMETER   REMOTE   COMPLIANCE TOOLS   
Securing your first remote office: Solutions for less than $10,000

<< PREVIOUS | NEXT >>: Quiz: Securing your first remote office
 TIPS & NEWSLETTERS TOPICS 


How to set up a UTM firewall to secure a remote office


David Strom, Contributor
03.06.2009
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


SearchSecurity.com Security School
This tip is part of SearchSecurity.com's special Integration of Networking and Security School. For additional information on remote office security, visit our Securing your first remote office: Solutions for less than $10,000 lesson page.

There are several vendors that offer managed network services appliances for remote offices, which are often called Unified Threat Management (UTM). These products typically include a firewall, VPN and intrusion detection features, along with antivirus screening tools and an assortment of other security measures. That covers a lot of ground, and this technical tip demonstrates what is involved in configuring and maintaining this type of protection using firewall/VPN appliances from Check Point Software Technologies, SonicWall and Fortinet.

What the three products have in common is some form of managed network services offering, so that they can update their features, antivirus signature files and patches without any IT intervention. A monthly subscription fee is required for this service, but in turn there's no need to worry about maintaining these boxes.

Check Point has its Safe@Office brand of appliances that are offered for the SMB space, which advantageously run similar software to the larger Check Point firewalls. That can be helpful if your remote office has its own RADIUS authentication server, because it can be set up to use that same directory for network authentication. Check Point recently announced the UTM-1 appliance for larger enterprise customers. The other two vendors started their businesses in the SMB arena and are working their way up to offer products for larger enterprises.

Taking a look at the setup routines, SonicWall has one of the easiest ones, with several wizards that walk you through the basics, including a setup wizard that has a mandatory password change. It looks like the screen below.


SonicWall wizards aid with initial setup.

The Check Point main services screen is shown below. You can see at a glance the particular service, whether the subscription is active or not, and if the box is connected to the managed services controller back at Check Point headquarters.


The Safe@Office services screen.

Fortinet has something similar, but places it on the main status screen as shown below. This provides information on the various subscriptions (and more importantly, when they expire), firmware version of the box and some summary usage statistics too. Also useful is the icon at the top of the screen that indicates the port status of the box; in our case, nothing is connected to it other than the WAN port, but if PCs were connected, these ports would be illuminated. There is also a command-line console window at the bottom of the screen shot which users can type in.


Fortinet's main status screen.

SonicWall's main status screen is shown below, and it has less information than Fortinet's, with basic information about ports, subscriptions and alert messages.


The main system status screen from SonicWall.

SonicWall has a separate services screen that goes into more detail about each managed network service, and it looks like the screen shown below, where license counts and the subscription period are enumerated.


SonicWall's services description.

Each of the three products has an intrusion detection and prevention subsystem that requires a fair amount of work to set up and maintain. Check Point calls its product Smart Defense and has a detailed series of configurations that cover the usual threats by protocol type, as shown below.


Check Point's Smart Defense configuration.

Fortinet has something similar with its IPS, with a long list of attack vectors and radio buttons to enable/disable them. SonicWall separates its IPS and IDS. The IPS looks like the following, with a long list of potential exploits for which you can enable detection.


The SonicWall IPS configuration screen.

Its IDS subsystem is in a separate location, and looks like the following screen.


SonicWall's IDS configuration screen.

Lastly, there are some other configurations that are required, such as setting up antivirus or antispyware features. Check Point's antivirus setup screen is fairly simple and looks like the following screen.


Check Point's antivirus setup screen.

SonicWall has a more complex configuration for its antispyware. You can choose various threat levels, particular protocols to scan (such as Web, FTP or the various email protocols), and set up various antispyware policies for its scanner to check, as shown by the screen below.


SonicWall's antispyware feature.

Fortinet includes the ability to scan instant messaging traffic on its box, and setting that up will take you to the screen shown below. You can automatically allow or block one of the three major IM vendors (AOL, Microsoft and Yahoo) and set up policies for particular users as well. This is something that is often found in much more expensive products and can be a useful security tool.


Fortinet's instant messaging configuration.

About the author:
David Strom is one of the leading experts on network and Internet technologies and has written extensively on the topic for nearly 20 years. He has held several editorial management positions for both print and online properties, most recently as Editor-in-Chief for Tom's Hardware. In 1990, Strom created Network Computing magazine and was the first Editor-in-Chief establishing the magazine's networked laboratories. He is the author of two books: Internet Messaging (Prentice Hall 1998) which he co-authored with Marshall T. Rose and Home Networking Survival Guide (McGrawHill/Osbourne; 2001). Strom is a frequent speaker, panel moderator and instructor and has appeared on Fox TV News Network, NPR's Science Friday radio program, ABC TV's World News Tonight and CBS-TV's Up to the Minute.


Rate this Tip
To rate tips, you must be a member of SearchMidmarketSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


<< PREVIOUS | NEXT >>: Quiz: Securing your first remote office
VIEW ALL IN THIS CATEGORY


RELATED CONTENT
Securing your first remote office: Solutions for less than $10,000
Real-world best practices for securing remote offices
Quiz: Securing your first remote office
Securing your first remote office: Solutions for under $10,000

Integrating security into networks
Four things to remember about server virtualization security concerns
Five network security issues to avoid
How to rework your network infrastructure for security
Streamlining your network security infrastructure
Network-based integrity monitoring keeps website hacks in check
How to make data loss prevention tools affordable and manageable for midmarket
PCI DSS requirement: Building and maintaining a secure network
Network security begins with device discovery and assessment
NAC Basics: Laying the groundwork
Understand the differences in network access control solutions

Wireless network security management
Remote phone lock and GPS tracking counter smartphone security risks
Find remote mobile device wipe solutions on a budget
Avoid security risks of Free Public WiFi wireless ad hocs
Five steps to eliminate rogue wireless access
Three steps to achieve security for smartphones within a budget
Real-world best practices for securing remote offices
Quiz: Securing your first remote office
Safe but simple wireless authentication
Choosing midmarket wireless authentication server infrastructure options
How to build a secure wireless connection

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts