We review the WatchGuard Firebox T30 and explain why its enterprise-class security features can benefit small businesses.
Firewall appliances were originally designed to be an upgrade from a standard router by adding network protection from undesirable internet traffic. However, some have evolved way beyond this to become all-in-one network security devices offering unified threat management (UTM), with anti-spam, antivirus, web-content filtering and advanced protection such as an intrusion prevention system (IPS).
If you’re wondering how much all this costs, you may be in for a pleasant surprise with WatchGuard's Firebox T30, which offers enterprise-class security measures for a reasonable price. It's aimed squarely at small businesses or remote offices lacking on-site IT expertise, as WatchGuard's innovative RapidDeploy delivers fast plug-and-play installation services.
This fiery red desktop box isn't lacking in the hardware department either. It sports five Gigabit ports for LAN, WAN and ‘demilitarized zone’ (DMZ) duties, and it's big on performance, with a fast UTM throughput of 135Mbits/sec.
Pricing for the Firebox T30 starts at $1,144 for a basic support package or $1,552 for a one-year subscription to the Basic Security Suite, which includes anti-spam, gateway antivirus, IPS, web-content filtering, application controls, HTTPS inspection and WatchGuard's reputation-enabled defence. Bumping that up to $2,179 adds Total Security Suite, which also includes data-leak prevention (DLP) and advanced persistent threat (APT) blocker services. But our advice is to shop around because we've seen some big discounts for the Firebox T30 online.
The Firebox T30 isn't for beginners but you don't have to be a networking guru either: we followed the web console's quick-start wizard to provide firewall-protected internet access in less than five minutes. Proxies are used to control all traffic types, with WatchGuard catering for HTTP, HTTPS, FTP, DNS, SIP, H.323, POP3 and SMTP.
These used to be tricky to set up, but the latest firmware lightens the load by providing wizards for each of them. Web content filtering is now a painless three-step process in which we provided a name for the blocking action, chose from more than 120 URL categories and applied it to HTTP and HTTPS traffic.
The wizard also handled firewall configuration and automatically created new policy rules for our web-content filters. Anti-spam measures are just as easy to apply using the SpamBlocker service, where we created actions to tag dubious emails as spam, suspect or bulk.
Simplicity is the watchword when it comes to gateway antivirus. It only took us a few seconds to activate – again using a wizard, which displayed the proxy actions we could enable. You'll need gateway antivirus running to use the APT blocking service; it transparently scans incoming files, creates MD5 hashes and compares them with the Lastline cloud service to root out known malware.
We were impressed with the T30's application controls, which provide a searchable list of around 1,800 apps with all the main social networks represented. Rules are very versatile, too.
For example, we could let users log in to their Facebook and Twitter accounts, but block them from uploading media, playing games, Liking, following and retweeting.
The T30 functions as a central wireless controller for WatchGuard's own access points, and its fourth LAN port is also PoE-enabled (Power over Ethernet). After pairing a WatchGuard AP200 model with the appliance, we used the main web console to assign SSIDs to its 2.4GHz and 5GHz radios, enforce wireless security, enable client isolation and apply separate proxy policies to the port to which it was connected.
Enterprises and managed services providers will appreciate WatchGuard's RapidDeploy cloud service, which will allow them to send new appliances to remote offices and have them receive a configuration file once they've been powered up (you need a local appliance to create a file and upload it to your cloud support account).
Once the remote appliance has been registered and RapidDeploy enabled, it will then download and apply the file as soon as it connects to the internet.
The web console provides plenty of monitoring facilities for network and proxy activity, which can be augmented with WatchGuard's freely available Log Server software. The T30 also sports the FireWatch feature found in WatchGuard's Dimension management software. This displays sets of coloured squares, the size of which indicates the level of activity for sources, destinations, policies, applications and interfaces.
We've explained the benefits of buying a firewall appliance previously. If you're in the market for one, the Firebox T30 should be on your shortlist. It offers a remarkable range of features and powerful performance at sensible price.
WatchGuard also offers a Wi-Fi version, the Firebox T30-W (from $1,372) or an even higher-performance model, Firebox T50 (from $1,811). However, for many small businesses, the Firebox T30 offers everything they'll need in a network security appliance.