Skip Links

Network World

  • Social Web 
  • Email 
  • Close

UTM firewall review: SonicWall smashes speed records

New appliance offers enterprise-level UTM performance
By Joel Snyder , Network World , 04/07/2008

Last month, SonicWall rolled out its next-generation unified threat management firewall appliance geared for the enterprise. In our exclusive test of the Network Security Appliance E7500, results show that SonicWall has, indeed, crashed through the speed barrier.

This box offers 1.3Gbps of UTM performance, which is nearly triple the speed of the fastest product in our comparative UTM test last November (See comparative UTM test).


How we tested SonicWall
Archive of Network World tests
Subscribe to the Network Product Test Results newsletter

While SonicWall has not changed much on the surface of its firewall, there are dramatic differences in the internal architecture that yield performance gains that leapfrog the throughput numbers of the SonicWall Pro product line. This makes UTM features including intrusion-prevention system (IPS), antivirus, antispyware, and content filtering cost-effective because they can run at gigabit speeds. (Compare UTM products in UTM Buyer’s Guide.)

Fifth generation multicore performance

SonicWall's NSA firewall line, based on a family of multi-core security processors from Cavium, is called the company's "generation 5 product." The new hardware (six models have been announced already) is slated to entirely replace the company's old Pro series.

SonicWall NSA E7500 Version 5.0
SonicWall
4.01
Price: $25,000
Pros: Very high-performance UTM features; small size; low power consumption; high interface density; redundant power supplies and fans; SonicPoint wireless LAN management system and wireless IDS
Cons: Manageability of UTM features limited, especially in IPS; Web-based management system had difficulty handling complex policies in firewall or NAT; firewall configuration flexibility held back by built-in configuration limits
Scorecard
Performance 25% 4.75 Scoring Key:
5
: Exceptional
4
: Very good
3
: Average
2
: Below average
1
: Subpar or not available
Intrusion prevention 15% 2.50
Antivirus 15%
4.50
VPN 15% 4.00
Management 15% 3.50
Hardware architecture 10% 4.50
Power5% 4.00
TOTAL SCORE 4.01
Click to see: SonicWall net results

The high-end E7500 that we tested has a 16-core Cavium CPU, with each core operating at 600MHz. One core is dedicated to system management, while the other 15 are used for security processing, including firewall, VPN and other UTM features such as antivirus, IPS and content filtering. Also built into the CPU is hardware acceleration for cryptography (useful in VPNs), compression, and regular expressions, which compare a pattern against a string, and are heavily used in most IPS rule sets. SonicWall claims it took 18 months to port its existing operating system to effectively make use of the multicore capabilities of the new hardware.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (7)
Login
Forgot your account info?

Fake ResultsBy Anonymous on August 10, 2008, 9:23 pmYou are not comparing apples to apples. If you pick the top sonicwall box and compare it to a mid level cisco box..... It looks like soncwall paid for this one....

Reply | Read entire comment

Mail FrontierBy Anonymous on May 27, 2008, 1:03 pmI am trying to find the language blocking site, which I no longer can find. Max@americangathering.org

Reply | Read entire comment

agreeBy mee on May 13, 2008, 3:27 pmi a gree with you it realy does suck cause it blocks every thing

Reply | Read entire comment

stupidBy Anonymous on May 13, 2008, 3:24 pmi hate you

Reply | Read entire comment

traffic profile...By nin4086 on May 12, 2008, 3:40 pmI would like to know what kind of traffic profile was used in the test...1.3Gbps seems pretty low for a 16-core processor

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Magic Quadrant for Application Delivery Controllers

Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses...

Vulnerability Management For Dummies

Download this concise book "Vulnerability Management for Dummies," to learn about the simple steps...

The ROI and TCO Benefits of Data Deduplication for Data Protection in the Enterprise

This paper examines and quantifies the costs and benefits of backup with deduplication storage as...

Webcasts

Transforming the Enterprise WAN Edge: Video from Cisco

Life on the edge of your WAN has changed dramatically. With the need to deliver advanced services,...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.