Simple clear advice in plain English

Aladdin Esafe Gateway 4

Content filtering software.

Unlike most of the vendors in this group test, Aladdin has just the one product to filter and manage both web and email traffic. Esafe Gateway 4 is available in several formats, starting with a virtual appliance CD that, when booted, installs a security hardened Red Hat Linux kernel and the Esafe software on the gateway machine. You can also buy it ready-installed on an IBM rackmount server or as a Windows 2000 or Solaris app.

Deployment is much the same in each case, with options to configure the Esafe gateway as a proxy server or as a transparent bridge. The advantage of the latter is that no reconfiguration of clients is needed, and there should be very little impact on network throughput. There's also a version for use with Checkpoint firewalls and a separate Esafe Mail product to police internal mail traffic on Exchange servers. It's also possible to cluster gateways, to balance load and provide failover redundancy.

The Esafe gateway inspects all HTTP (web), SMTP (email) and FTP (file transfer) traffic passing in and out of the network, taking a multilayered approach to securing that information. This starts with anti-virus filtering using Aladdin's 32bit scanning engine (an external scanner can also be used), with facilities to selectively screen out attachments and handle compressed files. Macros can be stripped from files retrieved from untrusted sources and Java and ActiveX controls similarly filtered and selectively blocked or allowed, with facilities specifically to stop Denial of Service (DoS) attacks.

When a virus or other suspect attachment is detected, the Esafe gateway can automatically blacklist the source site. More general access to the web can similarly be controlled by URL and IP address blocking, with facilities to specify restricted sites manually and to optionally download a categorised database licensed from Surfcontrol.

Keyword filtering is another option, with customisable lists supplied as standard, while users attempting to access prohibited sites can either be shown warning messages or redirected to a custom URL. FTP traffic is similarly filtered, as are all email messages, both incoming and outbound, with options to prevent host mail servers being used to relay messages.

Email controls can be applied to any SMTP system and disclaimers added to outgoing mail. Outbound content can be checked for keywords to prevent distribution of confidential or offensive materials. You can also block incoming unsolicited (spam) messages using a mix of restricted sender lists, SMTP header and keyword filtering. None of the more sophisticated anti-spam mechanisms found in the Surfcontrol or Marshall products is present.

With the Esafe Virtual Appliance you use a web interface to manage the gateway while a separate Windows utility, Econsole, is used to set up and manage security policies. This can configure and manage multiple gateways running on different platforms, although not as one using global policies.

The Econsole interface is easy to get to grips with and we particularly liked the realtime graphing of activity. On the downside, you can define VIP users and excuse them some of the controls, but you can't tailor access policies based on user identity or group membership. The built-in reporting is basic too, although there is support for the Crystal Reports report generator (not included) and the ability to export logging information to a common SQL database for further analysis.

Another disappointment is Aladdin's approach to instant messaging (IM) security. Esafe Gateway 4 can identify popular IM and point-to-point (P2P) protocols, but only to allow or block them. A facility to disallow file transfers while still allowing conversations is planned for the next version.

With both web and email filtering, Esafe Gateway is attractive for small businesses, especially those with limited technical resources, where the virtual appliance deployment is useful. Services from Aladdin will keep the software up to date. You don't get the granularity of control some of the dedicated web and email tools offer, but that's not necessarily a bad thing, as configuring and managing the more advanced filtering products can be an issue in itself.

Contact: Aladdin Knowledge Systems 01753 622 266
www.esafe.com

Reader Comments

display:none  

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Our verdict

Suggested price

£2115

Manufacturer

Great benefits for subscribers!

Poll

Which is your preferred web browser

Jargon Buster

Computing terms explained in plain English

VoIP

Voice over IP. The routing of voice conversations over the internet, which is cheaper than the telephone...

Great shopping deals from Computeractive