Saturday March 13, 2010 3:49 AM AEST
 
Latest Comments
"Thanks fot the information you provided! It's really useful site and I'm glad that came across ..."
by Lora | Mar 13, 2010 1:00 AM
 
"Mifare 1K,4K,DESfire 4K,Sle4442,T5577,PVC card,KeyFob,ID card,Magstripe card Dear Sir/Madam, ..."
by Jucy | Mar 12, 2010 1:05 PM
 
"Hi Everybody Guys>> How r u? >>I Am S.M.Moshin Arafat (jony) >> I Am a Very Simple Person & I ..."
by Moshin Arafat | Mar 12, 2010 10:29 AM
 
"Sounds funny. Did they ever tell the customers in plainly-worded language that the co-lo space ..."
by Dave - The Network Mule | Mar 11, 2010 10:28 AM
 
"Sunglasses of wto-store.com www.wto-store.com Versace Sunglasses http://wto-store.com/catego..."
by Luxury Handbags 100% Authentic, 2010 Lastest Styles, Buy Now! | Mar 10, 2010 8:59 PM

DFL-2500

  • Email a Friend
  • Print Page
DFL-2500
Product Info
Supplier:
Product Rating
Features:  3
Ease of Use:  3
Performance:  4
Documentation:  3
Support:  2
Value for Money:  4
Overall Rating:  Overall Rating
 
For: Well-designed interface makes complicated tasks easy.
Against: Weak logging, and default admin connection is unsecured.
Verdict: Offers an interesting mix of powerful features.
By Jon Tullett
Jul 10, 2006 12:00 AM
Tags: DFL-2500 | (Firewalls | 2006)
D-Link’s DFL-2500 offers more network control than we expected, and does it at a good price for its class.

D-Link’s DFL-2500 offers more network control than we expected, and does it at a good price for its class.

Strangely, the unit ships with all its ports configured to different network segments. This might be handy, but most will probably immediately reconfigure them. By default, only one port can connect to the management interface, and while this can be changed, it took a bit of trial and error to find it.

We were surprised that the HTTP connection to the management GUI makes no effort at all to secure the admin password – the login is passed in completely plain text over the wire. The unit does offer HTTPS connections, but the manual made no mention of this.

A pop-up wizard walks you through basic set-up. A nice touch is an automatic roll-back to the previous configuration if you fail to manually confirm that the interface is still accessible after any major configuration change.

To get the firewall working in a real environment, you need to spend time setting up definitions – networks, services, authentication groups and so on. These are all abstracted before being expressed in rules, so rules cannot be set up without a definition. This gets tiresome, but only because we are used to other products letting us skimp on what is, after all, much better practice. And the various pages all link together, making the process easy to use.

Apart from using syslog, we could find no way to log and report on the device’s activities, which is astonishing. Like the role definitions, best practice suggests that managing logs elsewhere is a better idea, but this is an omission that may raise some eyebrows.

The unit can remotely manage other boxes via its Zone Defense feature – to create enterprise-wide blacklists in the event of an IDS trigger, for example.

As well as its filtering capabilities, this is actually a surprisingly flexible router too, with more traffic routing features than we would expect. This will be useful to some environments, although we would normally expect the box to be behind a real router anyway, so it might be redundant.

And the routing features do make the process of setting up some rules more complicated than they need to be.

The system provides IDS and you can create custom rules, but not your own signatures.

This well-priced unit has plenty of features and is very flexible. The interface has rough edges and you need a bit of network know-how to really use it to its full potential, but in the right hands this would be a very good solution indeed.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Access Control Whitepapers