Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
SP2 beta for Windows Server 2008, Vista available
Nokia's new N97 vs. the iPhone: Latest smartphone showdown
Wanted: A long-term data center strategy
FastSoft technology speeds downloads for Getty Images
Open source developers set out software road map for 2020
VMware expands desktop virtualization capabilities
FBI warns of holiday cyber scams
Cisco renews call for national broadband strategy
Apple antivirus advice 'big to-do about nothing'
U.S. Open used Web filtering to prevent online gambling
Google Earth used by terrorists in India attacks
Verizon trounces competition in wireless quality survey
Mumbai terrorist attacks don't deter technology companies
Google layoffs: 10,000 jobs being cut, report claims
Experts to Feds: Sign the DNS root ASAP
Security /

Blue Coat Security Gateway 800

Combining caching with Web security

Related linksToday's breaking news
Send to a friendFeedback
Related linksToday's breaking news
Send to a friendFeedback


Last month CacheFlow changed its name to Blue Coat Systems, reflecting a new focus on policing the Web. The company's new beat cop is its Security Gateway 800, which combines proxy caching with fine-grained control over Web, Secure Sockets Layer and streaming media traffic. The SG800 handles security tasks that firewalls can't, such as blocking executable objects, viruses and other undesirable content on a per-object basis.

The new product also enhances CacheFlow's respectable caching performance. In our tests, the device moved traffic at rates of 1,200 transaction/sec, with no performance hit when advanced features are enabled. This performance and its ease of use made it worthy of our World Class Award.

Housed in a 1U (1.75-inch) rack-mountable enclosure, the SG800 we tested features 2G bytes of RAM, four redundant 68G-byte SCSI drives, two 10/100M bit/sec Ethernet interfaces and a copper gigabit Ethernet interface.

Advertisement:

Setting up the SG800 is simply a matter of entering four parameters on a front-panel LED. Everything afterward can be done via CacheFlow's well-known intuitive Web interface.

The SG800 retains the same caching features as previous versions of the vendor's custom CacheOS operating system. Chief among these is "prefetching" of objects. If users often visit a site where pages contain a large number of images or other embedded objects, the cache will "prefetch" all objects so they can be served from the cache.

The user interface now includes a Visual Policy Manager (VPM), a Java-based applet with a look and feel that will be familiar to users of Check Point Software or NetScreen Technologies firewalls.

Where VPM differs from most firewalls is in its much finer grained control over access to Web, SSL and streaming media content. The SG800 lets users screen content based on HTML content type, executable content type, user's browser type, time of day and hundreds of other parameters. It's possible to block clients using Microsoft Internet Explorer 5.0 from requesting a group of URLs containing ActiveX objects during business hours.

VPM is equally strong when it comes to access policies. Users or groups can be allowed or denied access based on individual IP addresses, subnets, NT LAN Manager, Remote Authentication Dial-In User Service or Lightweight Directory Access Protocol authentication.


How we did it
Interactive Scorecard and NetResults
Archive of Network World reviews
Subscribe to the Product Review newsletter

The SG800 can scan for viruses and objectionable content through use of third-party plug-ins. With these plug-ins, the SG800 will set up rules to deny content that contains known viruses or content such as violence, nudity, hate speech or other user-defined policies.

Security concerns

As powerful as these security features can be, we are concerned with the product's remote management. While the SG800 supports encrypted access via SSL or Secure Shell (SSH), neither of these services is enabled by default. Instead, the default access is via a Web browser or telnet. As a result, an unauthorized user could intercept passwords or management commands.

Similarly, the SG800 can upload its logs to another server, but the transfer method is FTP, yet another unsecure protocol.

Unsecure default configurations are problematic in any device, let alone one called a "security gateway." Users are well advised to enable SSH and SSL before putting the SG800 into production networks.

Speed demon

We ran several benchmarks to evaluate the SG800's performance (see How we did it). We measured basic transaction rate and transaction rates with logging and rule sets enabled.

To get a sense of how the SG800 would handle a meaningful production load, we used Web Polygraph, the open source tool that has become a de facto standard for measuring cache performance.

Polygraph's Polymix-4 traffic load uses a blend of content types, object size distributions, object popularity, object freshness and cacheability. Polygraph also models delays and packet loss typically added by WAN links.

The SG800 handled a peak load of 1,202 transaction/sec in our tests, and it's possible that the device could go even faster. The 1,202-transaction/sec rate represents a horsepower limit of our test bed, and not necessarily a limit of the SG800.

We conducted our initial tests with access logging disabled. Because access logging is commonly used in production settings, we ran the test once again with logging enabled.

The good news is that transaction rates were just about the same: Even with logging turned on, the SG800 moved 1,191 transaction/sec.

We ran the same test with 10 access policies defined — five "allow" rules and five "denies" — the SG800 moved around 1,174 transaction/sec.

One cost to adding logging and access rules was that the number of errors increased.

In our baseline test, there were virtually no errors. With logging enabled, there were errors on about 3.5% of transactions, and there were errors on about 7% of transactions with logging and access rules enabled.

Most errors involved transaction timeouts, but in all cases overall response times remained fairly even.

The SG800 offers a unique combination with its fine-grained access control and its caching features that help network professionals save bandwidth and speed response times.

How we did it

To measure cache performance, we used Web Polygraph, an open source HTTP generation and analysis tool. Besides the Blue Coat Security Gateway, our test bed included three pairs of Dell Optiplex GX100 machines with 256M bytes of RAM running FreeBSD 4.3 and Web Polygraph and an Extreme Networks Summit 7i switch that tied all the systems together.

We used the Polymix-4 workload and Release 2.7.6 of the Polygraph software. We used the default parameters of 10 phases, including two peak load phases during which we took our measurements. We also enabled FreeBSD's Dummynet feature, which simulates client-side WAN latencies of 40 msecs per packet and a 0.05% probability of packet loss on the server side. We did not add latency or packet loss for the clients.

Security Gateway 800
4.6
Rating
Company: Blue Coat Systems, (408) 220-2200, Cost: $6,000 to $30,000 (as tested). Pros: Fine-grained access control; a snap to use; strong performer. Cons: Encryption of administrative traffic disabled by default.  

Security Gateway 800
Features 30% 
5
Performance 30%  5
Ease of use 20%  5
Security 10%  2
Price/value 10%  4
TOTAL SCORE
4.6
Individual category scores are based on a scale of 1 to 5. Percentages are the weight given each category in determining the total score. Scoring Key: 5: Exceptional showing in this category. Defines the standard of excellence; 4: Very good showing. Although there may be room for improvement, this product was much better than the average; 3: Average showing in this category. Product was neither especially good nor exceptionally bad; 2: Below average. Lacked some features or lower performance than other products or than expected; 1: Consistently subpar, or lacking features being reviewed.

RELATED LINKS

Newman is president of Network Test in Westlake Village, Calif., an independent benchmarking consultancy. He can be reached at dnewman@networktest.com.


NW Test Alliance

Global Test Alliance

Newman is also a member of the Network World Global Test Alliance, a cooperative of the premier reviewers in the network industry, each bringing to bear years of practical experience on every review. For more Test Alliance information, including what it takes to become a member, go to www.nwfusion.com/alliance.

CacheFlow becomes Blue Coat
CacheFlow, a caching pioneer that launched in 1996, is exiting the caching market to focus on appliances used to safeguard networks against Web-based threats. Network World, 08/26/02.

IDS tools smarten up
Customer dissatisfaction with signature-based intrusion-detection systems leads to anomaly-based appliances. Network World, 09/09/02.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.