Welcome!

Open Source Authors: Ignacio M. Llorente, Carmen Gonzalez, Michael Meiner, Liz McMillan, Amy Lindberg

Related Topics: Linux, Security

Linux: Article

The Astaro Security Gateway 320

The good news is that Astaro makes it easy to protect yourself with a family of security gateway appliances

If you're responsible for network security, then you know that yours is a job fraught with worry over spam, network intrusions, viruses, and internal hazards like rogue servers, internal malicious activity, and web surfing control. The good news is that Astaro makes it easy to protect yourself with a family of security gateway appliances. The ASG320, its model for mid-sized business and enterprise divisions, packs a high-value punch. It doesn't take a string of Linux servers to set up a security infrastructure, just a single appliance that's certainly a more economical solution. The ASG320 is more than a firewall since it provides network segment configuration, intrusion protection, packet filtering, and an IPSEC VPN configuration toolset.

Initialization and setup of the ASG320 is a snap with a Web interface similar to many home office-style wireless routers. The Astaro WebAdmin management platform lets you get going immediately. In minutes, passwords are set, the license files are uploaded, and the configuration is ready to be customized. The ASG320 allows for complete control in configuring internal- and external-facing network interfaces and system users. The network services section comes with several common protocols already defined on the default ports, and a clean and simple utility for defining custom services.

As might be expected, the ASG320 provides configuration interfaces for routing, DHCP, and NAT and provides a traffic accounting utility. The accounting information and local logs can be browsed or queried through the ASG320's intuitive log query utility, which lets you highlight or filter information by time span and/or message type.

The Intrusion Protection System (IPS) on the ASG320 recognizes attacks automatically and blocks them before they can reach your network. A key feature of the IPS is its Portscan Detection. Many attacks begin as would-be intruders scan networks to find which services are available. The Portscan Detection feature detects these scans and alerts you to the potential attack. The IPS also provides severity-based alerts and notification. The system recognizes and records detected and blocked packets and sends alerts based on your configuration so you can make adjustments based on incoming or outgoing traffic. Powerful exclusion policies can be created through the Advanced section of the Intrusion Protection interface. Here you can customize performance-tuning parameters for common server connections such as HTTP, DNS, SMTP, SQL, or Telnet.

The ASG320's Packet Filter provides great flexibility in setting up firewall rules. The ASG320 blocks all packets by default, and requires you to define which packets can pass. Commonly needed settings and utilities such as SYN rate limiting and the definition of ICMP policy are handled with ease.

Virus Protection on the ASG320 is achieved via content filters where the ASG320's Proxy Content Manager scans passing e-mails for potentially dangerous or unwanted content. The offending messages are identified and blocked automatically. Through the Proxy Content Manager these messages are deferred or quarantined, and can be subject to automatic cleanup. The Proxy Content Manager can also be configured to send you a daily spam digest.

The ASG320 provides an IPSEC VPN toolset. With the IPSEC VPN configuration area, you can configure the types of connections that your network will support, policies for those connections, and local and remote keys with which those connections authenticate. Additional features include configuring L2TP over IPSEC connections and CA management so you can manage your own X.509 Certificate Authority. Here the ASG320 extends well beyond the notion of a firewall simply as a packet filter. IPSEC VPNs can create complex management and the ASG320 simplifies and centralizes that management.

While it was pegged with internally simulated traffic and nakedly exposed to the ravages of raw Internet traffic, the ASG320 sang. It detected ping and port scans and dozens of simultaneous connection attempts during the test. Forensic analysis of the system logs revealed attacks consistent with well-publicized viruses, but the sources were stopped dead. The ASG320 handled the traffic and reported attack bursts as expected, while suffering only slightly from the immense load it was operating under. Its intrusion protection and packet-filtering features performed as needed in an enterprise network.

The ASG320 comes with several management utilities to simplify administration. With its configuration backup utility you can save or upload your ASG320's configuration, or configure the system to mail the file to a specified e-mail address with the option of encryption. The ASG320 lets you update virus definitions, system patches, and security features using its System Up2Date service. SNMP access and traps are available services, as is remote system logging.

If you're worried about the ASG320 being a single point of failure, fear not for it comes with integrated high availability. High Availability Menu is configured with the first ASG320 set in Normal Mode and the second in Hot Standby Mode. Besides the data transfer connections, the standby system can monitor the active system via a serial interface.

Conclusion
With a rich interface, and a completely configurable host encompassing thousands of functions, the ASG320 can still make it easy to secure your network. It's designed for the data center and appears to benefit from a design driven by requirements that most data center managers would expect. System management, intrusions detection, packet filtering, and virus and spam protection are provided in an economical package with little management required beyond the initial configuration. Considering the price and functionality combined with ease of use this is an excellent solution for the small and medium-sized data center.

See Sidebar

More Stories By Matt Frye

Matt Frye is the Review Editor at Linux.SYS-CON.com, and Engineer in New Product Introduction and Emerging Network Solutions at Tekelec.

Comments (1) View Comments

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


Most Recent Comments
LinuxWorld News Desk 07/17/05 01:25:42 PM EDT

Product Review: The Astaro Security Gateway 320
If you're responsible for network security, then you know that yours is a job fraught with worry over spam, network intrusions, viruses, and internal hazards like rogue servers, internal malicious activity, and web surfing control. The good news is that Astaro makes it easy to protect yourself with a family of security gateway appliances. The ASG320, its model for mid-sized business and enterprise divisions, packs a high-value punch.

@ThingsExpo Stories
How do APIs and IoT relate? The answer is not as simple as merely adding an API on top of a dumb device, but rather about understanding the architectural patterns for implementing an IoT fabric. There are typically two or three trends: Exposing the device to a management framework Exposing that management framework to a business centric logic Exposing that business layer and data to end users. This last trend is the IoT stack, which involves a new shift in the separation of what stuff happens, where data lives and where the interface lies. For instance, it's a mix of architectural styles ...
The Internet of Things will put IT to its ultimate test by creating infinite new opportunities to digitize products and services, generate and analyze new data to improve customer satisfaction, and discover new ways to gain a competitive advantage across nearly every industry. In order to help corporate business units to capitalize on the rapidly evolving IoT opportunities, IT must stand up to a new set of challenges. In his session at @ThingsExpo, Jeff Kaplan, Managing Director of THINKstrategies, will examine why IT must finally fulfill its role in support of its SBUs or face a new round of...
Connected devices and the Internet of Things are getting significant momentum in 2014. In his session at Internet of @ThingsExpo, Jim Hunter, Chief Scientist & Technology Evangelist at Greenwave Systems, examined three key elements that together will drive mass adoption of the IoT before the end of 2015. The first element is the recent advent of robust open source protocols (like AllJoyn and WebRTC) that facilitate M2M communication. The second is broad availability of flexible, cost-effective storage designed to handle the massive surge in back-end data in a world where timely analytics is e...
We are reaching the end of the beginning with WebRTC, and real systems using this technology have begun to appear. One challenge that faces every WebRTC deployment (in some form or another) is identity management. For example, if you have an existing service – possibly built on a variety of different PaaS/SaaS offerings – and you want to add real-time communications you are faced with a challenge relating to user management, authentication, authorization, and validation. Service providers will want to use their existing identities, but these will have credentials already that are (hopefully) i...
Cultural, regulatory, environmental, political and economic (CREPE) conditions over the past decade are creating cross-industry solution spaces that require processes and technologies from both the Internet of Things (IoT), and Data Management and Analytics (DMA). These solution spaces are evolving into Sensor Analytics Ecosystems (SAE) that represent significant new opportunities for organizations of all types. Public Utilities throughout the world, providing electricity, natural gas and water, are pursuing SmartGrid initiatives that represent one of the more mature examples of SAE. We have s...
"Matrix is an ambitious open standard and implementation that's set up to break down the fragmentation problems that exist in IP messaging and VoIP communication," explained John Woolf, Technical Evangelist at Matrix, in this SYS-CON.tv interview at @ThingsExpo, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
The Internet of Things will greatly expand the opportunities for data collection and new business models driven off of that data. In her session at @ThingsExpo, Esmeralda Swartz, CMO of MetraTech, discussed how for this to be effective you not only need to have infrastructure and operational models capable of utilizing this new phenomenon, but increasingly service providers will need to convince a skeptical public to participate. Get ready to show them the money!
One of the biggest challenges when developing connected devices is identifying user value and delivering it through successful user experiences. In his session at Internet of @ThingsExpo, Mike Kuniavsky, Principal Scientist, Innovation Services at PARC, described an IoT-specific approach to user experience design that combines approaches from interaction design, industrial design and service design to create experiences that go beyond simple connected gadgets to create lasting, multi-device experiences grounded in people's real needs and desires.
P2P RTC will impact the landscape of communications, shifting from traditional telephony style communications models to OTT (Over-The-Top) cloud assisted & PaaS (Platform as a Service) communication services. The P2P shift will impact many areas of our lives, from mobile communication, human interactive web services, RTC and telephony infrastructure, user federation, security and privacy implications, business costs, and scalability. In his session at @ThingsExpo, Robin Raymond, Chief Architect at Hookflash, will walk through the shifting landscape of traditional telephone and voice services ...
Scott Jenson leads a project called The Physical Web within the Chrome team at Google. Project members are working to take the scalability and openness of the web and use it to talk to the exponentially exploding range of smart devices. Nearly every company today working on the IoT comes up with the same basic solution: use my server and you'll be fine. But if we really believe there will be trillions of these devices, that just can't scale. We need a system that is open a scalable and by using the URL as a basic building block, we open this up and get the same resilience that the web enjoys.
The Internet of Things is tied together with a thin strand that is known as time. Coincidentally, at the core of nearly all data analytics is a timestamp. When working with time series data there are a few core principles that everyone should consider, especially across datasets where time is the common boundary. In his session at Internet of @ThingsExpo, Jim Scott, Director of Enterprise Strategy & Architecture at MapR Technologies, discussed single-value, geo-spatial, and log time series data. By focusing on enterprise applications and the data center, he will use OpenTSDB as an example t...
The Domain Name Service (DNS) is one of the most important components in networking infrastructure, enabling users and services to access applications by translating URLs (names) into IP addresses (numbers). Because every icon and URL and all embedded content on a website requires a DNS lookup loading complex sites necessitates hundreds of DNS queries. In addition, as more internet-enabled ‘Things' get connected, people will rely on DNS to name and find their fridges, toasters and toilets. According to a recent IDG Research Services Survey this rate of traffic will only grow. What's driving t...
Enthusiasm for the Internet of Things has reached an all-time high. In 2013 alone, venture capitalists spent more than $1 billion dollars investing in the IoT space. With "smart" appliances and devices, IoT covers wearable smart devices, cloud services to hardware companies. Nest, a Google company, detects temperatures inside homes and automatically adjusts it by tracking its user's habit. These technologies are quickly developing and with it come challenges such as bridging infrastructure gaps, abiding by privacy concerns and making the concept a reality. These challenges can't be addressed w...
Explosive growth in connected devices. Enormous amounts of data for collection and analysis. Critical use of data for split-second decision making and actionable information. All three are factors in making the Internet of Things a reality. Yet, any one factor would have an IT organization pondering its infrastructure strategy. How should your organization enhance its IT framework to enable an Internet of Things implementation? In his session at Internet of @ThingsExpo, James Kirkland, Chief Architect for the Internet of Things and Intelligent Systems at Red Hat, described how to revolutioniz...
Bit6 today issued a challenge to the technology community implementing Web Real Time Communication (WebRTC). To leap beyond WebRTC’s significant limitations and fully leverage its underlying value to accelerate innovation, application developers need to consider the entire communications ecosystem.
The definition of IoT is not new, in fact it’s been around for over a decade. What has changed is the public's awareness that the technology we use on a daily basis has caught up on the vision of an always on, always connected world. If you look into the details of what comprises the IoT, you’ll see that it includes everything from cloud computing, Big Data analytics, “Things,” Web communication, applications, network, storage, etc. It is essentially including everything connected online from hardware to software, or as we like to say, it’s an Internet of many different things. The difference ...
Cloud Expo 2014 TV commercials will feature @ThingsExpo, which was launched in June, 2014 at New York City's Javits Center as the largest 'Internet of Things' event in the world.
SYS-CON Events announced today that Windstream, a leading provider of advanced network and cloud communications, has been named “Silver Sponsor” of SYS-CON's 16th International Cloud Expo®, which will take place on June 9–11, 2015, at the Javits Center in New York, NY. Windstream (Nasdaq: WIN), a FORTUNE 500 and S&P 500 company, is a leading provider of advanced network communications, including cloud computing and managed services, to businesses nationwide. The company also offers broadband, phone and digital TV services to consumers primarily in rural areas.
"There is a natural synchronization between the business models, the IoT is there to support ,” explained Brendan O'Brien, Co-founder and Chief Architect of Aria Systems, in this SYS-CON.tv interview at the 15th International Cloud Expo®, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
The major cloud platforms defy a simple, side-by-side analysis. Each of the major IaaS public-cloud platforms offers their own unique strengths and functionality. Options for on-site private cloud are diverse as well, and must be designed and deployed while taking existing legacy architecture and infrastructure into account. Then the reality is that most enterprises are embarking on a hybrid cloud strategy and programs. In this Power Panel at 15th Cloud Expo (http://www.CloudComputingExpo.com), moderated by Ashar Baig, Research Director, Cloud, at Gigaom Research, Nate Gordon, Director of T...