Home > Security News > Review: Juniper's newest WiFi device big on functionality, low on cost
Security News:
EMAIL THIS

Review: Juniper's newest WiFi device big on functionality, low on cost

By Sandra Kay Miller, Contributor
02 Aug 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

NetScreen-5GT Wireless
Juniper Networks, www.juniper.net
Price: Starts at $940

Juniper Networks' NetScreen-5GT Wireless device packs a lot of security into an affordable, highly configurable package for SMBs and branch offices. Despite somewhat difficult installation/configuration and weak documentation, this device is a steal at less than $1,000.

The 5GT Wireless bundles a stateful deep-packet inspection firewall, IPSec VPN and AV into a wireless access point. It supports up to four WLANs, each of which can employ different encryption and authentication methodologies. The device supports a wide range of security protocols, including WEP, WPA (both AES and TKIP) and IPSec, and an equally impressive collection of authentication methods—EAP (TLS, TTLS and PEAP), PSK, LDAP, RADIUS, RSA, SecureID and LDAP.

The 5GT Wireless provides firewall protection, including NAT, through five 10/100 Mbps Ethernet ports and an ADSL port. The device can be administered through a graphical Web interface, command line, console connection, Telnet or SSH. Unfortunately, the Rapid Deployment Wizard doesn't live up to its name, and we opted to initialize and configure the device manually. There are too many unexplained settings choices, and a wrong choice affects the rest of the install. For a device with such extensive security options, the documentation was minimal.

Our testing simulated the device's ability to create multiple security zones, such as those a small business or remote location might deploy. We provided open wireless access to the Internet for customers, secured wireless access for on-site vendors using WEP, and the most secure wireless access for employees, using AES WPAv2 (802.11i). Additionally, the employees' wired network was run through the 5GT Wireless.

General wireless radio operations, such as antenna diversity, operation mode, transmission rates and powers, and channel and MAC address control, are very configurable. SSIDs were created by simply choosing a button in the SSID list, which opened an extensive array of settings, such as WEP authentication and encryption methods, and WPA authentication, binding and broadcast and isolation methods—all on a single page. You can also monitor active wireless associations and conduct site surveys to ascertain the current state of wireless activity.

Once the WLANs were defined, we created and assigned detailed policies for each, with options to permit or deny more than 70 different services (such as HTTP, FTP and SSH) and 18 applications (including SMTP, POP3, IMAP). For example, we allowed AOL on our open wireless connection, but denied it on our vendor and employee WLANs.

Other policy settings include AV; VPN tunneling and logging; granular control over NAT, authentication, URL filtering, traffic shaping, users and groups; and configurable alarm thresholds.

The IPSec VPN offers the same elements of security and interoperability found in Juniper's NetScreen enterprise boxes. Reporting and logging are as comprehensive as the device's security capabilities. Extensive system logs, counters for hardware, flow and zones, interface bandwidth, policies, wireless statistics, and active users can be sent to security administrators via the console, interface, e-mail, SNMP, syslog, WebTrends and NSM.

The Netscreen-5GT Wireless delivers an enterprise-caliber capability at an SMB price.

Sandra Kay Miller wrote this for the August 2005 issue of Information Security magazine.

Tags: Wireless LAN Design and SetupVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Wireless LAN Design and Setup
Wireless network guidelines for PCI DSS compliance
Best Wireless Security Products
How to prevent wireless DoS attacks
Lesson 4 quiz: How to use wireless IPS
Wireless intrusion prevention systems: Overlay vs. embedded sensors
Rogue AP containment methods
How to monitor WLAN performance with WIPS
The role of VPN in an enterprise wireless network
Wireless AP placement basics
Lesson 3 quiz: Who goes there?
Wireless LAN Design and Setup Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
evil twin  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts