Google Answers Logo
View Question
 
Q: Firewalls Benchmarking Research ( Answered,   2 Comments )
Question  
Subject: Firewalls Benchmarking Research
Category: Computers > Software
Asked by: ashleyf1-ga
List Price: $180.00
Posted: 14 Apr 2003 12:21 PDT
Expires: 14 May 2003 12:21 PDT
Question ID: 190380
I’d like some help in doing some research and analysis of firewalls.
If it helps, these should be firewalls for web servers / web
applications (not sure it makes much difference though?).

More specifically I’d like the following:
 
1. 9 firewalls to be reviewed 
 
2. 3 should be free-low cost, 3 should be mid-market, 3 should be high
end
 
3. You will need to define the pricing brackets for these 3 groups –
‘free-low cost’, ‘mid-market’ and ‘high end’
 
4. You will need to pick the 3 in each bracket which you feel are best
of breed for that market bracket
 
5. For each firewall I need the following:  
 
- Company name 
- Product name 
- Pricing information 
- Contact information (URL, telephone, address) 
- Summary of pros / cons 
- Product features 
- Technical information 
- Support / Customer Service information
- Links to relevant reviews (industry and consumer)
 
Much of the above information should be available on the vendor’s web
sites. I would expect you to add value as follows:
 
- knowing which firewalls to select 
- including some intelligent analysis in the “Summary of pros/cons”
section though this should be brief
- leaving no blanks and keeping the structure/quantity/quality of your
review of each consistent

6. Your recommended top resources for the research you do for this

7. Your criteria for selecting the 9 firewalls

8. A list of other firewalls + URLs that you looked at but rejected
Answer  
Subject: Re: Firewalls Benchmarking Research
Answered By: livioflores-ga on 17 Apr 2003 09:50 PDT
 
Hi ashleyf1!!

This is an amazing question, thank you for ask us about this topic.

I did the research using your criteria. 
First of all I must tell you how I clasified the selected firewalls in
different categories. I did it not based in the price but based in
features.
The less featured category selected was pure firewall solution with
small amount of ads, the research on this results in freeware
firewalls.
The mid featured category includes firewalls plus some additional
service in support or more featured products, this results in the pro
versions of the freeware solution in some cases, an also results in
prices in the middle of the range (Prices between $30 and $50).
The high category includes security suites, that is products wich
offer a complete protection (ad blockers, coocking managers, password
storage protection, antivirus, mail protection, etc.). This results
also in higher priced products (Prices above $65).

To do the research I used my own experience with basic and pro
versions (Low and Mid categories), but also used sources like:
"Firewall Info":
http://lists.gpick.com/pages/Firewall_Info.htm

"Personal Firewall Software Reviews" from FirewallGuide.com.
This is a great page that must be the starting page for any research
about Firewalls. Take a look on it:
http://www.firewallguide.com/software.htm

"Home PC Firewall Guide":
"The purpose of the Home PC Firewall Guide is to provide easy access
to independent, third-party reviews of Internet security products for
home, telecommuter, and SOHO (small office, home office) end-users."
http://www.firewallguide.com/

"What Is A Firewall?", a complete article about firewalls.
Summary:
Part 1: Intro to Firewalls 
Part 2: Types of Firewalls
Part 3: Pros and Cons
http://netsecurity.about.com/library/weekly/aa030503a.htm

------------------------
BASIC FREEWARE FIREWALLS
------------------------

Sygate 
------
- Company name: Sygate Technologies, Inc. 

- Product name: Sygate Personal Firewall
 
- Pricing information: Free for personal/home (non-commercial) use
only. For business licenses, multiple seat licenses or advanced users
Sygate Personal Firewall PRO is available
  
- Contact information: http://www.sygate.com
Sygate Technologies Headquarters
6595 Dumbarton Circle
Fremont, CA 94555
510.742.2600
510.742.2699 | fax
 http://www.sygate.com/contact.htm


- Product features:  
Multi-Layered Firewall Engine
Advanced Rules for:
          ·TCP/UDP/ICMP/IP 
          ·Network Interface 
          ·Application (NEW) 
Protocol Driver Level Protection
Backtrace/WHOIS Feature
Configurable Email Security Alerts


- Product Overview:
Sygate Personal Firewall is a user-friendly PC firewall and personal
desktop security solution. It is the first bi-directional intrusion
defense system designed for home users while with advanced protocol
driver-level protection and code-insertion prevention. Sygate Personal
Firewall ensures your personal computer is completely protected from
malicious hackers and other intruders while preventing unauthorized
access from your computer to a network. In essence, Sygate Personal
Firewall makes your protected machines invisible to the outside world.
Sygate Personal Firewall, gives you complete confidence that your
precious business, personal, financial and other data is safe and
secure. If that isn't enough, Sygate Personal Firewall includes
advanced active-scan vulnerability assessment to pinpoint your
weaknesses and fine-tune your security policy.
Sygate Personal Firewall delivers unobtrusive, highly configurable,
enforceable rule-based security policy by constantly operating in the
background of your PC. Policies regarding applications, trusted IP
addresses, ports, protocols and scheduling can be customized to
support and secure any network configurations or requirements.
Designed with high performance in mind, Sygate Personal Firewall
delivers top-notch security without sacrificing your computing power.
Whether you're working, banking, gaming or chatting, Sygate Personal
Firewall is protecting your computer by actively looking for hostile
intruders and Trojan horse applications. If an intrusion attempt
occurs, Sygate Personal Firewall detects it in real-time and blocks it
by default. You are immediately notified and, with your approval, your
Internet connection is adjusted to prohibit further attacks. Likewise,
if an unauthorized application on your system attempts to access the
Internet, Sygate Personal Firewall blocks it by default, advises you
of the situation and waits for your approval before proceeding
further.
Sygate Personal Firewall is extremely easy to use. Even the most
inexperienced web-surfer can enjoy the Internet with complete
confidence and security. Sygate Personal Firewall easily installs on
your system by automatically detecting your Internet connection and
settings. Simply turn it on and you are ready to go with advanced
protection for all of your networking needs.
Summarized from "More info" page of Sygate Personal Firewall:
http://soho.sygate.com/products/shield_ov_info.htm
  

- Support / Customer Service information:
Sygate Product Forums support is free to all users of Sygate software.
Note that support for Sygate Personal Firewall is provided via the
forums only.
Support via Sygate Product Forums can be obtained by starting a new
thread in the support section of Sygate Product Forums., be sure to
review the forum rules before posting and allow 1-2 business days for
reply to your post.:
http://forums.sygatetech.com/

You can also see the SPF 5.0 Online help file:
http://soho.sygate.com/support/documents/spf_help/spf5_toc.htm


- Summary of pros / cons:
 Pros:
Easy installation, default setting is good enough in the most cases,
customizable rules for ports and applications, excellent Back Trace
feature, hide your OS and browser, and check DLLs to ensure that
they're not malicious code in disguise, e-mail notifications when
attacks are logged. Stealth navigation.

 Cons:
Minimal technichal support, defficult ICS manage, requires some
knowledgement about network security to do a properly configuration,
the information provided by alerts are technicaly detailed but they
provide no practical advice, users without training will likely make
poor decisions.


- Links to relevant reviews:
Industry:
"Sygate Personal Firewall PRO 5.0" By Serdar Yegulalp:
http://www.pcmag.com/article2/0,4149,643040,00.asp

"Sygate Personal Firewall" by Mike Magee:
http://www.theinquirer.net/?article=4895

"Sygate Personal Firewall 5.0 Pro *Top Product!* "   By Scot Finnie:
http://www.scotsnewsletter.com/33.htm#review1

See also "Sygate® Technologies Articles & Reviews":
http://soho.sygate.com/news/art.htm


Costumer:
"CNET Reviews":
http://www.cnet.com/software/0-352108-1218-9992539.html?tag=dir

"VersionTracker":
http://www.versiontracker.com/dyn/moreinfo/windows/17771#comments

"MouthShut.com":
http://www.mouthshut.com/readproduct/925040417-1.html

--------------------------------------------------

Zone Alarm:
----------

- Company name:  Zone Labs

- Product name: Zone Alarm Personal Firewall

- Pricing information: Free for personal use. For business licenses or
advanced users Zone Alarm PLUS and PRO versions are available.

- Contact information: http://www.zonelabs.com

U.S. Headquarters
Zone Labs, Inc.
1060 Howard Street
San Francisco, CA 94103
USA
Tel: 415/341-8200 
Fax: 415/341-8299 

European Headquarters
Zone Labs, GmbH
Düsseldorfer Str. 40a
65760 Eschborn, Germany
Tel: +49 6196 773-670 
Fax: +49 6196 773-6777 

http://www.zonelabs.com/store/content/company/contact.jsp


- Product features:
Easy-to-use interface gets new users up and running quickly 
New in-client logging provides log filtering, sorting and real-time
analysis
Multi-layer protection system shields you from inbound and outbound
threats
Basic MailSafe email protection stops .VBS email viruses 
Context-sensitive help system, quick-start tutorial, quick-reference
text column, and new security overview panel guide you through
installation, use, and threat evaluation
All new AlertAdvisor offers instant security advice from the experts
at Zone Labs—you never face security threats alone*
Zone management area lets you easily share files with computers and
networks you trust while simultaneously blocking everyone else
Active network indicator tells you what computers and networks you're
trusting


 - Support / Customer Service information:
Zone Labs don't provide ZoneAlarm users direct technical support, but
they do support ZoneAlarm Pro and ZoneAlarm Plus.
The ZoneAlarm User Community exists to provide users of ZoneAlarm a
way to help each other get more out of the leading free firewall:
http://www.zonelabs.com/store/content/support/userCommunity/userComm_agreement.jsp


-Product Description: 
"ZoneAlarm makes it easy. Unlike other personal firewalls, ZoneAlarm
protects automatically from the moment it's installed - no programming
required. ZoneAlarm barricades your PC with immediate and complete
port blocking. And, then runs in Stealth Mode to make your PC
invisible on the Internet - if you can't be seen, you can't be
attacked.
ZoneAlarm delivers simplicity without compromising your security. A
getting started tutorial explains controls and alerts to get you up
and running quickly. And, to keep you confident that you're always
protected, intuitive color-coded alerts rate security risks - in real
time. "
From VersionTracker.com:
http://www.versiontracker.com/dyn/moreinfo/windows/19815
 

- Summary of pros / cons:
Pros:
Installation and setup is virtually automatic 
Use of system memory is small
Customizable level of security
Stealth navigation
Basic e-mail verification

Cons:
No technical support. 
User must decide whether to allow outgoing communication but less than
adequate help provided for novices.
 

- Links to relevant reviews:
Industry:
"MouthShut.com":
http://www.mouthshut.com/readreview/6531-1.html

"PCmedix":
http://www.pcmedixwebs.com/zone.htm

Note: most of the reviews are dedicated to the Pro version. I will
talk about this version in the "mid-market" section.

Costumer:
"VersionTracker.com":
http://www.versiontracker.com/dyn/moreinfo/windows/19815

"Dooyoo":
http://www.dooyoo.co.uk/computers/applications/zone_labs_zonealarm/_review/299313/

---------------------------------------

-Kerio:
-------


- Company name: Kerio Technologies Inc
  
- Product name: Kerio Personal Firewall.
  
- Pricing information: Free for personal use, $39 for business. 

- Contact information: http://www.kerio.com/us/kerio.html
Corporate headquarters
Kerio Technologies Inc.
2855 Kifer Road, Suite 103
Santa Clara, CA 95051
USA
Phone: + 1 (408) 496-4500
Fax: + 1 (408) 496-4506
info@kerio.com


- Support / Customer Service information:
Email Support
Available for registered and demo users of Kerio Personal Firewall;
customers must include their serial number to receive email support.
Most emails will be answered within 1 business day.
Email: support@kerio.com

Free Kerio Personal Firewall users please note:
Submit only comments or concerns. General questions will not be
supported. You may refer to our yahoo group for the latest betas, as
well as feedback from other users:
http://groups.yahoo.com/group/keriofirewall .

Steve Gibson's siteis also a helpful resource and offers several
firewall related news groups:
http://www.grc.com 

You can also see the online library:
http://www.kerio.com/manual/kpf/en/

Or dowload a manual from "Kerio Personal Firewall Manual" page:
http://www.kerio.com/us/supp_kpf_manual.html


- Product features:
Blocks all externally orginated IP traffic and drops the packets,
rendering the desktop invisible to potential intruders.
Three security settings for easy configuration; default setting sends
alerts for all types of traffic. Permit or deny an indivdual
incidence, or create permanent filter rules instantly.
MD5 application signatures protect the computer from Trojan horses
imitating trusted programs.
Trusted address group option limits desktop access to known users or
computers only.
Opened Connections overview displays clearly what each application is
doing at any given moment.
Admin authentication keeps users from changing security policy on
their own; KPF can be run as a service to ensure the computer is
protected from startup.
Encrypted remote administration allows, syslog reporting and
configuration export allow for easy deployment of security settings to
remote computers

  
- Product Overview: 
"Three types of security
The user can choose between three types of security policies: minimum,
medium and maximum. Minimum security allows all communication except
user-defined restrictions. When switched to medium security Kerio
Personal Firewall operates in learning mode. If an unknown application
tries to initiate network communication, a dialog will appear,
depending on the user's answer the communication will be forbidden,
permitted temporarily or permitted always. Maximum security blocks all
communication between the computer and the network. In addition to
this, KPF offers the ability to configure custom security policies.

Stateful inspection
Stateful inspection is the real "brain" of Kerio Personal Firewall.
Based on analysis of previous communication, the firewall decides
whether activities of authorized applications corresponds with
assumptions and security rules. Thus, KPF eliminates the possibility
of hackers using authorized channels for their mischief.

Authorized applications
In order for Kerio Personal Firewall to be able to identify authorized
applications correctly, an encrypted signature (MD5) is issued to each
application. The application then uses this signature while trying to
initiate any communication. As this signature is always unique, it
will prevent any trojan horse application's attempt to disguise itself
as a trusted application.

Defining secure zones
Should it be necessary to permanently permit communication to remote
applications or grant certain users permanent access to the computer,
the user can set a range of trusted IP addresses or only one IP
address from which access will be allowed. These IP groups can be
defined for each protocol or application. The user can even define the
time ranges that communication will be allowed.

Application activity overview
An overview of all active applications (open connections) will give
the user a clear idea of what individual programs are doing at any
given moment. Thus, the user can find which application is sending
data out or which is receiving data from outside and which application
is in stand-by mode. KPF also reports the amount of throughput (RX/TX)
that has been processed by each application. Kerio Personal Firewall
can be then used to easily point at suspicious behavior of a certain
application.

Remote administration
Kerio Personal Firewall parameters can be set either directly at the
computer where KPF is installed or remotely from any computer on the
Internet via an encrypted channel. Access to administration can be
forbidden. This will prevent company employees from changing the
security policy on their computers.

Activity protocols
A report about all activities is recorded in the so-called log file
with several levels of detail. By analyzing this log file the user can
determine what commucniation was performed by individual
applications."
From "KPF´s  Overview" page:
http://www.kerio.com/us/kpf_overview.html


- Summary of pros / cons:
Pros:
Very customizable, Kerio offers an incredible amount of flexibility
and power through its rules.
MD5 Signature Support.
Kerio allows for trusted applications and trusted address groups,
remote administration, and login authentication.
Use of minimal system resources.
Complete event logging. 
Complete stealth navigation.

Cons:
Need to manual disable of NetBios for the first time.
Non-friendly alerts.
The customization are recommended only for advance users.


- Links to relevant reviews
Industry:
"Project Magazine":
http://www.projectmagazine.com/v3i7/keriov3i7.html

"Computer Active Online":
http://www.computeractive.co.uk/Download/1131791

"HackFix Project":
http://www.hackfix.org/software/configure/tiny.html

"Plexon.com":
http://www.plexon.com/winroute_personal.html

"ZDNet Australia":
http://www.zdnet.com.au/reviews/software/security/story/0,2000023554,20269579-5,00.htm


Costumer:
"Download.com":
http://download.com.com/3302-2092-9032150.html

              *************************---**********************
----------------------------------
ENHANCED FIREWALLS (Pro versions):
----------------------------------


Zone Alarm Pro
--------------

- Company name:  Zone Labs

- Product name: Zone Alarm Pro

- Pricing information: Single user licence with 1 year of updates and
support $49.95; with 2 years of updates and support $69.90.

- Contact information: http://www.zonelabs.com

U.S. Headquarters
Zone Labs, Inc.
1060 Howard Street
San Francisco, CA 94103
USA
Tel: 415/341-8200 
Fax: 415/341-8299 

European Headquarters
Zone Labs, GmbH
Düsseldorfer Str. 40a
65760 Eschborn, Germany
Tel: +49 6196 773-670 
Fax: +49 6196 773-6777 

http://www.zonelabs.com/store/content/company/contact.jsp


- Product features:
The same that the ZA Personal Firewall:
·Easy-to-use interface gets new users up and running quickly 
·New in-client logging provides log filtering, sorting and real-time
analysis
·Multi-layer protection system shields you from inbound and outbound
threats
·Context-sensitive help system, quick-start tutorial, quick-reference
text column, and new security overview panel guide you through
installation, use, and threat evaluation
·All new AlertAdvisor offers instant security advice from the experts
at Zone Labs—you never face security threats alone*
·Zone management area lets you easily share files with computers and
networks you trust while simultaneously blocking everyone else
·Active network indicator tells you what computers and networks you're
trusting
plus:
·Improved Ad Blocking 
·Cookie Control 
·Advanced MailSafe e-mail attachment protection 
·Automatic Intrusion Blocking 
·Improved Program Control 
·Enhanced Hacker Tracking* 
·Pop-up Ad Control 
·Automatic Network Detection 
·Automatic Software Updates 

 - Support / Customer Service information:
Zone Labs provides ZoneAlarm Pro users direct technical support.

"Costumer Service and Support" page:
http://www.zonelabs.com/store/content/support/support.jsp

"ZoneAlarm® Pro 3.x Support Center" page:
http://www.zonelabs.com/store/content/support/3zapMain.jsp

Zone Labs Web-Based Technical Support for ZoneAlarm Pro and ZoneAlarm
Plus:
http://www4.zonelabs.com/cgi-bin/servlet/support/support_req_fp.pl

Product Help Documentation:
http://www.zonelabs.com/store/content/support/3zapHelpDocs.jsp

The ZoneAlarm User Community provides users of ZoneAlarm Pro a way to
help each other get more out of their firewall:
http://www.zonelabs.com/store/content/support/userCommunity/userComm_agreement.jsp


-Product overview from Zone Labs:
Any personal computer connected to the Internet is a potential target.
Hackers randomly barrage Internet connected PCs with "pings" or "port
scans", probing to find unprotected PCs. Once found, a hacker can
compromise your PC with a dangerous Internet threat - Trojan horse,
spyware or malicious worm.
ZoneAlarm Pro's TrueVector® technology combines a personal firewall
with Program Control to protect your PC from intrusions and hostile
attacks. ZoneAlarm Pro's firewall barricades your PC with immediate
and complete port blocking. And, then runs in Stealth Mode to make
your PC invisible on the Internet - if you can't be seen, you can't be
attacked.
Unlike other personal firewalls, ZoneAlarm Pro includes Program
Control to protect against known and unknown Internet threats. Program
Control monitors all outbound traffic to prevent rogue programs from
transferring your valuable data to a hacker. With ZoneAlarm Pro,
you're in control with the ability to specify which programs, known or
unknown, can be trusted to access the Internet.


- Summary of pros / cons:
Pros:
Installation and setup is virtually automatic 
Use of system memory is small
Customizable level of security allows a fair amount of flexibility.
Stealth navigation
Advanced MailSafe e-mail attachment protection recognizes and
quarantines some known attachment types.
Includes an ad-blocking tool and cookie management; hides PC ports
from hackers; new interface is easier to use.

Cons:
Intruder information is a little difficult to work.
No phone support.


- Links to relevant reviews
Industry:
"Epinions.com":
http://www.epinions.com/content_67824619140

"ZDNet Australia":
http://www.zdnet.com.au/reviews/software/security/story/0,2000023554,20269579-8,00.htm

"CNet Reviews":
http://www.cnet.com/software/0-352108-1205-8943601-1.html?tag=dir

"PC MAgazine":
http://www.pcmag.com/article2/0,4149,643042,00.asp


Costumer:
"CNet Reviews":
http://www.cnet.com/software/0-352108-1218-8943601.html?tag=subnav

"Epinions.com":
http://www.epinions.com/cmsw-Utilities-All-Zone_Alarm/display_~reviews

"ZDNet":
http://downloads-zdnet.com.com/3302-2092-10188476.html

"VersionTracker.com":
http://www.versiontracker.com/dyn/moreinfo/windows/13225

"MouthShut.com":
http://www.mouthshut.com/readproduct/925013993-1.html

------------------------------------

-Sygate Personal Firewall Pro:
------------------------------


- Company name: Sygate Technologies, Inc. 

- Product name: Sygate Personal Firewall Pro
 
- Pricing information: 
1 User License $39.95 
1 User License (With 1-Year Upgrade Protection) $47.95 
3 User License $99.95 
3 User License (With 1-Year Upgrade Protection)  $119.95 
5 User License $149.95 
5 User License (With 1-Year Upgrade Protection) $179.95 
10 User License $269.95 
10 User License (With 1-Year Upgrade Protection) $359.95 


- Contact information: http://www.sygate.com
Sygate Technologies Headquarters
6595 Dumbarton Circle
Fremont, CA 94555
510.742.2600
510.742.2699 | fax
 http://www.sygate.com/contact.htm


- Product features:
Protocol Driver-Level Protection
Backtrace/WHOIS Feature
Configurable Email Security Alerts
Active Response
Anti-MAC & Anti-IP Spoofing
OS Fingerprint Masquerading
Stealth Browsing
Broadcast Traffic Filtering
Server Application Blocking
Enhanced IP Fragmentation Protection
Enhanced DoS Protection
Application-Based IDS (Intrusion Detection System)
Application DLL Authentication
Pre-Service Start Protection
Firewall Termination Prevention
Auto Trojan Termination
Running Application Termination
Password Protected Exit
Logging Enhancements 
Common UDP Port Name Support
Application Configuration per Adapter
ICMP Traffic per Application
Advanced Rule Enabling/Disabling
Enhanced Security Setting Customization
Full ICS Support
Full Active Directory Support
If you wnat more detail on this features please visit:
http://soho.sygate.com/products/pro/whatsnew_pro.htm#security


- Product Overview:
"Sygate Personal Firewall PRO has redefined the personal firewall
market with a multi-layered shield of network, content, application,
and operating system security. Sygate Personal Firewall PRO protects
your system from intrusions designed to exploit vulnerabilities in
Internet and Intranet communication. It is the ultimate desktop
security solution trusted by professionals and relied upon by millions
of users.
Network Layer -- Secure Internet Connections
Sygate Personal Firewall PRO is the first personal firewall that
offers real protocol driver-level protection, preventing hostile
programs such as Trojan Horses and malicious mobile code from
accessing the network using their own protocol driver. With newly
added network layer protection measures and existing application level
protection, Sygate Personal Firewall PRO provides complete security
from the network to the application layer.
Content Layer -- Secure Trusted Traffic
Sygate Personal Firewall PRO is the first personal firewall with an
application-based intrusion detection system (IDS). Network layer
protection can ensure the inbound network packets are legitimate, but
it can do little about the contents hiding in the packets. The high
performance intrusion detection engine in Sygate Personal Firewall PRO
monitors network traffic content, and uses pattern matching to detect
a variety of attacks and probes, such as buffer overflows and stealth
port scans.
Application Layer -- Secure Component Integrity
Sygate Personal Firewall PRO secures systems from intrusions that
exploit vulnerabilities in applications to execute attacks. Sygate
Personal Firewall PRO verifies the integrity of every application that
attempts to communicate through a fingerprint that includes a MD5
checksum. In addition to that, Sygate Personal Firewall PRO
authenticates application dynamic link libraries (DLLs), preventing
hostile programs that masquerade as authorized applications from
compromising users’ data or system.
Operating System Layer -- Secure Process Interactions
Sygate Personal Firewall PRO is the first personal firewall that
integrates meaningful operating system layer protection, guarding the
legitimacy of outbound traffic. Sygate Personal Firewall PRO blocks
any traffic generated before its own service starts up, eliminating
the brief security policy vacuum. Sygate Personal Firewall PRO can
automatically terminate known attacks such as Trojans, Denial of
Service (DoS) Zombies. Sygate Personal Firewall PRO also has defense
mechanisms that prevent malicious code/and or users from disabling or
exiting the personal firewall.
By building a multi-layered shield around a system, Sygate Personal
Firewall PRO provides around-the-clock and multiplex protection for
data integrity and system safety. No wonder it is the ultimate desktop
security solution."
http://soho.sygate.com/products/pspf_ov.htm


- Support / Customer Service information:
Sygate provides its customers with online Product Forums, e-mail
support, and priority phone support.
Sygate Product Forums support is free to all users of Sygate software.
Sygate email support is free to all users of Sygate Home Network,
Sygate Office Network, and Sygate Personal Firewall PRO. Sygate email
support can be obtained by filling out the online support request
form:
http://soho.sygate.com/support/forms.htm

Sygate offers priority phone support for $75 per incident to users of
Sygate Home Network, Sygate Office Network, and Sygate Personal
Firewall PRO.


- Summary of pros / cons:
Pros:
Complete customization.
Application-Based Intrusion Detection System 
Protocol Driver-Level Protection 
Active Response 
Anti-IP & Anti-MAC Spoofing 
Application DLL Authentication 
Alerts are easy to understand
Stealth navigation.

Cons:
Expensive phone support.
No preconfigured rule sets for popular applications.
Need to be an advance user to do a complete safe customization.


- Links to relevant reviews:
Industry:
"PC Magazine":
http://www.pcmag.com/article2/0,4149,643040,00.asp

"PC World":
http://www.pcworld.com/news/article/0,aid,80404,00.asp

"CNet Reviews":
http://www.cnet.com/software/0-352108-1205-9992539-1.html?tag=dir


See also "Sygate® Technologies Articles & Reviews":
http://soho.sygate.com/news/art.htm


Costumer:
"CNet Reviews":
http://www.cnet.com/software/0-352108-1218-9992539.html?tag=subnav

--------------------------------------

-Outpost Firewall Pro:
----------------------


- Company name: Agnitum, Ltd.

-Product Name: Outpost Firewall Pro

- Pricing information:
Single licence  $39.95 
Family license that can be installed and used for up to five computers
$75.95
Business licences:
Single License $39.95 
2 User License $69.95 
3 User License $99.95 
5 User License $149.81 
10 User License $279.65 
25 User License $649.19 
50 User License $998.75 

- Contact information: http://www.agnitum.com/
Agnitum Limited Headquarters
Acropoleos Avenue 8
Mabella Court
Nicosia, Cyprus
info@agnitum.com.
http://www.agnitum.com/company/contact.html


- Product features:

Packet Filter:
System and application level filtering 
Wizard mode for automatic rule creation 
Firewall engine resides on the lowest possible level of the operating
system. This lets Outpost filter RAW_SOCKET and direct packet sending
into the drivers bypassing the TCP/IP stack
Detailed information on all connections and open ports 
Stealth mode support 
Anti-Leak (Outpost passes the famous LeakTest from grc.com) 
ICMP filtering 
ICS (Internet Connection Sharing) support 
Trusted IP group* 
Predefined system and application settings for all common tasks such
as browsing the web, allowing ICQ, allowing DNS or DHCP, etc
Easy NetBIOS rule creation for home and office networks 
Block all traffic or disable the firewall with one click 

General:
Highly customizable user interface 
Online, direct updating of plug-ins and settings for protection
against new attacks. Updates are automated, so you simply press Update
Now and reboot when prompted*
MD5 authentication 
Built-in log viewer 
Individual configurations for multiple users
Password protection of settings
Runs as a service

Plug-ins:
Full privacy protection against all kinds of active elements in e-mail
and WWW
Banner advertisement and pop-up window blocking 
Protection of e-mail from dangerous attachments and worms 
Every type of port scanning detection 
Internet attack blocking (nuke, etc.) 
Content filtering for parental control 
DNS caching to speed connection times

- Product information:
Agnitum Outpost is the first personal firewall that supports plug-ins.
Developers can implement this revolutionary technology to easily
expand Outpost's capabilities.
See "Benefits of the Outpost Firewall Pro",  there is a list of
features that you will find only in Outpost Firewall Pro:
http://www.agnitum.com/products/outpost/benefitspro.html

Publisher's Description  
From the developer: "Agnitum Outpost is the first personal firewall
for Windows developed with Open Architecture. The Open Development
Process proved its efficiency with the development of the Internet and
with Linux. No company can be as fast, flexible and innovative at
enhancing a closed product as thousands of developers from different
countries all working on an open one. Agnitum Outpost is the first
personal firewall that supports plug-ins. Sample plug-ins are included
to show how this revolutionary technology can easily be employed for
such tasks as Intrusion Detection, Advertisement Blocking, Content
Filtering, E-mail Guard and Privacy Control. Agnitum Outpost is
equipped with every feature a personal firewall should have. It is the
most functional firewall in the world. Outpost supports all the latest
security techniques and features such as: Full Stealth Mode,
Anti-Leak, and MD5 Authentication. Although Agnitum Outpost is setting
new standards in the firewall market, it looks like any Office
application! It needs no configuration before using and it starts
protecting your system as soon as it's installed. Compatibility is no
problem. Agnitum Outpost brings you peace of mind in any environment
no matter what: connection type you are using (dial-up, DSL, ISDN,
Cable, T1 or Satellite); MS Windows version (95,98, 98SE, ME, NT,
2000, XP); network (standalone PC, office network, home network, VPN
or Microsoft Internet Connection Sharing); application you are using
(every browser and e-mail client, Web or FTP server, ICQ, IRC, Online
Gaming and every other application imaginable)."
http://download.com.com/3000-2092-10116252.html?tag=lst-0-2


- Summary of pros / cons:
Pros:
A good balance between ease of use and protection.
Trusted Zone with a very simple user interface design.
Supports plug-ins.
High level of security.

Cons:
Non friendly manage of rules.
Default settings tend to be less secure than those of its better
competitors.
The DNS caching in particular tends to be a problem.
No phone support.


- Support / Customer Service information:
Agnitum offers Online Support, Self-Support and Online Community
Support options:
http://www.agnitum.com/support/


- Links to relevant reviews:
Industry:
"Review: Software Firewall Agnitum Outpost 1.0" by Scot Finnie
http://www.scotsnewsletter.com/38.htm#review1


Costumer:
"CNet Download.com"
http://download.com.com/3302-2092-10116252.html

            ****************************---*************************

-----------------------------------------
FULL FEATURED INTERNET PROTECTION SUITES:
-----------------------------------------


-Norton Internet Security:
--------------------------

- Company name: Symantec Corporation

- Product name: Norton Internet Security 2003  Professional Edition

- Pricing information: $99.95

- Contact information: 
World Headquarters
Symantec Corporation
20330 Stevens Creek Blvd.
Cupertino, CA 95014
tel +1 408 517 8000
www.symantec.com


- Product features:
"Key Features
     24-hour protection provides vital Internet security for dial-up,
DSL, and cable modem users.
     ENHANCED! Ad blocking now stops even more banner ads, pop-up
windows, pop-under windows, and other Web distractions.
     LiveUpdate automatically downloads new security updates.** 
Norton AntiVirus Professional Edition
     NEW! Detects and blocks viruses in instant message attachments. 
     ENHANCED! Automatically removes viruses, worms, and Trojan
horses.
      Scans and cleans both incoming and outgoing email messages. 
      ENHANCED! Script Blocking and new Worm Blocking can detect new
threats even before virus definitions are created for them.
      Data recovery protects important applications and files from
accidental deletion.
  
Norton Personal Firewall
     Intrusion Detection automatically blocks Internet attacks. 
     NEW! Alert Assistant indicates the level of an Internet threat
and helps you choose the best response.
     NEW! Security Monitor displays the status of your Internet
protection and lets you stop or resume all Internet traffic with a
click of a button.
       Automatic program control determines which programs can safely
connect to the Internet.
     
Norton Privacy Control
     ENHANCED! Prevents confidential information from being sent out
without your knowledge.
   
Norton Spam Alert
     NEW! Helps you keep junk mail out of your inbox by checking email
coming in via popular POP3 clients such as Microsoft® Outlook®
Express, Eudora®, and Netscape® Messenger.
   
Norton Productivity Control
     Lets you block access to distracting newsgroups and Web sites. 
     Allows you to set up different Internet access privileges for
each user.
Web Tools
     NEW! Web Cleanup deletes unneeded files left over from Internet
sessions.
     NEW! Connection Keep Alive helps prevent dial-up Internet
sessions from being interrupted."
http://www.symantec.com/sabu/nis/nis_pr/features.html

 
- Support / Customer Service information:
Free Online Support:
http://www.symantec.com/techsupp/activedata/asa_index.html

and paid Phone support ($29.95 per event):
http://www.symantec.com/techsupp/asa_ts_contact.html

"Support Policy " page.
http://www.symantec.com/techsupp/support_policy.html


- Summary of pros / cons:
Pros:
Friendly interface.
Complete security suite. 
Parental controls..
Autoblock feature, which shuts down any port scan. 
Has anti-Trojan rules and intrusion-detection.
Complete online support.

Cons:
Core frirewall isn´t better than the firewalls in the mid-market
range.
Only one year upgrades and support.
Hard uninstallation.

- Links to relevant reviews:
Industry:
"VnuNet.com":
http://www.vnunet.com/Products/Software/1138574

"Scot Finnie´s review":
http://www.scotsnewsletter.com/28.htm#review1

"PC Magazine":
http://www.pcmag.com/article2/0,4149,643039,00.asp

"IT Reviews":
http://www.itreviews.co.uk/software/s188.htm

"CNet Reviews":
http://www.cnet.com/software/0-352108-1205-20218674-1.html?tag=subnav

"Symantec Norton Internet Security - Reviews page":
http://www.symantec.com/sabu/nis/nis_pr/reviews.html


Costumer:
"CNet Reviews":
http://www.cnet.com/software/0-352108-1218-20218674.html?tag=subnav

------------------------------------

-McAfee Internet Security: 
--------------------------


- Company name: Network Associates, Inc.

- Product name: McAfee Internet Security

- Pricing information: This product is available as a single-user
license, it costs $69.99

- Contact information: 
Network Associates Corporate Headquarters
(including McAfee Security, Sniffer Technologies, and Magic Solutions)
3965 Freedom Circle
Santa Clara, CA 95054
972-963-8000

Sales VARS - reseller_support@nai.com
Enterprise Sales: 1-888-VIRUS-NO (1-888-847-8766)
Home User Sales: 1-801-772-1891 
OEM Sales: tonya_mecum@nai.com
Encryption Solutions: ebssales@nai.com
McAfee Service Provider Program: McAfeeMSP@nai.com


- Product features:

"KEY FEATURES 
Includes VirusScan® Home Edition 7 - Includes the latest version of
the award winning VirusScan anti-virus software to protect your system
from viruses, Trojans, Internet worms, harmful scripts, and other
malware. With automated updates and exclusive H.A.W.K. (Hostile
Activity Watch) protections, VirusScan keeps your computing free of
even the latest threats.
Includes McAfee® Firewall 4 - Includes the latest version of McAfee
Firewall. McAfee Firewall enables you to control the communications in
and out of your PC and helps keep hackers at bay. With powerful
Application Control, Intrusion Detection, and easy Home Networking and
Custom Rule Creation Wizards, McAfee Firewall provides essential
security for your Internet connection.
Spyware/Adware Protection - Helps enhance your privacy by rooting out
snooper programs that attempt to track your Web surfing habits. Now
you can easily find and shut down these tracking programs that often
piggyback on popular freeware utilities and games.
Extended Stealth Program Protection - Helps keep your PC free of
hidden key loggers that try to capture and steal your passwords and a
whole host of even more insidious programs that may be watching and
recording everything you do on your PC. Adds an essential layer of
protection against this growing threat to your privacy and security.
Pop-Up Blocker - Puts an end to those pesky and annoying pop-up ads so
prevalent on the Internet. Now you'll be able to surf the Internet
without these and other ads getting in your way and slowing you down.
Allow/Block Applications Per User - Lets you to control which
applications are available to different family members. Parents can
readily use installed programs while blocking access to younger family
members, protecting the family PC while restricting access to
questionable material.
Filtering of Usenet Newsgroups - Usenet is said to exemplify the best
and worst of the Internet. Now you can take charge of which newsgroups
and content various family members might be exposed to and filter out
objectionable material while retaining access to the wealth of
information Usenet provides.
Internet Content Filtering - McAfee Internet Security provides
effective content filtering for Web surfing, Chat, and popular instant
messaging applications, helping you protect your family from
objectionable content.
Identity Protection - McAfee Internet Security can secure your
personal identification and financial information (name, phone number,
address, credit card and bank account numbers), and prevent these and
other specified pieces of information about you or your family from
being transmitted out over the Internet without your permission,
enhancing your privacy and helping to protect your identity.
MRU Cleaner - Deletes the telltale trail left behind the files you've
opened and viewed recently. Enhances your privacy by clearing MRU's
(Most Recently Used) of Windows based utilities and many other popular
programs.
File Guardian Protection for Files, Folders & Drives - As an added
layer of protection for your data, File Guardian locks user selected
files and folders from prying eyes at your machine or even from across
the network.
McAfee Shredder - Securely erase files, folders, free space, and file
slack for increased privacy."
http://www.mcafee-at-home.com/products/internet-security/default.asp?m=1


- Support / Customer Service information:

·Technical Support
Network associates offers both free technical support and subscription
support, depending on the product. You can subscribe to one of its
support programs listed below:
-Online and Electronic Support (Free)
online support is immediately accessible to both the new user and the
experienced home user, 24-hours a day, seven days a week. Agent
assisted support, including Chat Now! and E-mail Express! is always
available, free of charge:
http://www.mcafeehelp.com/
-Pay-Per-Minute ($2.95/minute, first two minutes free)   
Get quick, need-based Priority product assistance, 7 days a week
(Available 5:00AM - 11:00PM PST). Fees appear on your local phone
bill. Call 900-3AT-HOME (900-328-4663). (U.S. Residents only)
Priority Support Single Incident (1 issue $39)
Need help with a problem? Technicians are available 7 days a week on a
toll-free line (Available 5:00AM - 11:00PM PST). To purchase a PIN and
receive the toll-free phone number. (US and Canadian Residents):
http://www.mcafeehelp.com/

http://www.mcafee-at-home.com/support/default.asp

·Customer Support
US
Network Associates
13465 Midway Road
Dallas, TX 75244
Phone: (972) 308-9960
Customer Service E-mail Form:
https://secure.nai.com/forms/support/mcafeeathome/custcare-form.asp 

Europe, Middle East, Africa
Customer Service
McAfee Consumer Products
Apollo Contact Centre
Units 2-6, Boucher Business Centre
Apollo road, Belfast BT12 6 HP
United Kingdom
www.mcafeehelp.co.uk

http://www.mcafee-at-home.com/support/cust-care/default.asp


- Summary of pros / cons:
Pros:
Includes Spyware/Adware protection.
Parental controls.
Automatically creates rules for popular apps
Uninstalls cleanly.

Cons:
Firewall not enabled by default after installation.
Requires configuration.
It can be hard to identify safe programs.
Creates large log files.


- Links to relevant reviews:
Industry:
"VnuNet.com":
http://www.vnunet.com/Products/Software/1136988

"PCMagazine":
http://www.pcmag.com/article2/0,4149,522745,00.asp

"Cnet Reviews":
http://www.cnet.com/software/0-352108-1205-20285070-1.html?tag=rating

"ZDNet":
http://www.zdnet.com/supercenter/stories/review/0,12070,561870,00.html

"PC BuyersGuide.com":
http://pcbuyersguide.com/solutions/security/McAfee_Internet_Security.html


Costumer:
"CNet Reviews":
http://www.cnet.com/software/0-352108-1218-20285070.html?tag=subnav

"PCWorld.com Product Finder":
http://pcworld.pricegrabber.com/search_getprod.php/masterid=590560/ut=c82b290e9ebe8a79

------------------------------------

-Freedom Security & Privacy Suite:
----------------------------------


- Company name: Zero-Knowledge Systems Inc. 

- Product name: Freedom Security & Privacy Suite

- Pricing information: $89.95 (1 year subscription)

- Contact information: 
Zero-Knowledge Systems Inc. 
2050 Bleury Street, Suite 740 
Montreal, Quebec 
Canada 
H3A 2J5 
http://www.zeroknowledge.com/alternate/contact.asp

http://www.zeroknowledge.com/default.asp


- Product features:
The suite of tools consists of:
 Freedom® Personal Firewall: The Freedom Personal Firewall controls
incoming and outgoing information and alerts you to any unauthorized
attempt to connect to your computer. It reduces the risk of external
threats, such as hackers, from remotely accessing your computer
without your knowledge.
 Freedom® Anti-Virus: The Freedom Anti-Virus provides you with
full-scale protection by blocking and destroying viruses, Trojan
horses and worms.
 Freedom® Parental Control: The Freedom Parental Control protects your
children from accessing inappropriate content on the Internet.
Additional Features
 Ad Manager: The Ad Manager speeds up your Web browsing experience by
allowing
you to choose whether or not to view a Web site's ads in your browser.
Freedom
maintains a list of sites whose ads can be turned off without
affecting the page's appearance.
 Form Filler: The Form Filler automatically fills in forms required
for online registrations and purchases. The information is encrypted
and stored on your computer to prevent its unauthorized release. Note:
This feature requires Microsoft Internet Explorer 4.0 or later.
 Keyword Alert: The Keyword Alert instantly scans all outgoing
communications for sensitive or identifying information, and warns you
before sending anything that contains it.
 Cookie Manager: The Cookie Manager gives you control over how much
information
Web sites record about your browsing habits. Freedom catches all
cookies and places them in your Cookie Jar. You have the option of
moving cookies that you do not want stored on your computer to the
Cookie Filter. When you quit Freedom, all the cookies that have been
added to the Cookie Filter are deleted.

See product DataSheet:
http://www.freedom.net/products/suite/GettingStarted.pdf?product=suite


- Support / Customer Service information:
Technical Support:
The Technical Support section will help you if you have questions
about software installation, setup, configuration, compatibilities and
product usability. You can search our Knowledge Center, or submit a
support request if you cannot find a solution to your problem
elsewhere on our web site.
http://www.freedom.net/support/technic.html

Costumer Service:
The Customer Service information area is dedicated to non-technical,
service-related inquiries such as purchasing and successfully
downloading our products.
custserv@digitalriver.com
http://www.freedom.net/support/customer.html


- Summary of pros / cons:
Pros:
Very powerful firewall protection, really one of the better ones (but
you need all the documentation for the configuration)

Cons:
Does not support ICS.
Hard configuration.


- Links to relevant reviews
Industry:
"PC World comparison chart":
http://www.pcworld.com/resource/article/0,aid,97430,pg,5,00.asp

"Cnet Reviews":
http://www.cnet.com/software/0-352108-1204-20688782.html

"Canada Computes":
http://www.canadacomputes.com/story.asp?id=8299&sb=337

"VnuNet.com":
http://www.vnunet.com/Products/Software/1129957

Note: in some reviews the Antivirus is not consider, this is because
it was added in the latest version, and the reviews are not updated.

----------------------------------------

The firewalls was selected by comparisons and good ratings from
industry reviewers. In some cases I have tested the firewalls in my
computer, this add a personal point of view, that is valuable I think.
Also was consider for final decision the costumers comments with the
only exception of the Freedom Security suite. This is because it is
not a popular software, it is difficult to understand the first time
used, but it is indeed a very good product (specially the core
firewall).
As I said you before, the main source for this research was:
"Personal Firewall Software Reviews" 
http://www.firewallguide.com/software.htm

The recommendations given in that page was a leading course to follow.
Also for reject software:
http://www.firewallguide.com/software.htm#Not Recommended

I can illustrate how I did the selections by showing a case:
"Tiny Personal Firewall"

This a full featured firewall which includes a system security suite.
I tested it in my PC and had severals troubles trying to keep my
computer working with this product installed and running. It was a
severe problem trying to install new software after firewall
installation. Next step was see some reviews; the better one is, from
PC Magazine:
http://www.pcmag.com/article2/0,4149,643041,00.asp

This review added to my personal experience lead me to reject it from
the list of the TOP 3 in its category (MID. The other options seems to
be more enhanced and work fine.

My personal selection (TOP 1)for each category are:

Kerio Personal Firewall
Zone Alarm Pro
Norton Internet Security


Additional list of Firewalls looked and tested:

BlackICE PC Protection:
http://blackice.iss.net/product_pc_protection.php

Kerio Personal Firewall 3 (beta version):
http://www.kerio.com/beta_section.html#kpf

Agnitum Outpost Free version:
http://www.agnitum.com/products/

Norton Personal Firewall:
http://www.symantec.com/sabu/nis/npf/

McAfee Personal Firewall:
http://www.mcafee.com/myapps/firewall/default.asp


For business and networks, the better choice are WinRoute Lite and Pro
versions.
"Kerio WinRoute Lite":
http://www.kerio.com/wrl_home.html

" Kerio WinRoute Pro".
http://www.kerio.com/wrp_home.html

For reviews of this software products see:
"Product Review - WinRoute Professional Firewall and Router"
http://www.theguardianangel.com/product_review_winroute_lite.htm

"Product Review - WinRoute Professional Firewall and Router"
http://www.theguardianangel.com/product_review_winroute_pro.htm


I hope this helps you. Please remember that this answer is not
consider finished until your are satisfied with it, so if you think
that a point is incomplete or missed, have troubles with links, need a
clarification, need a further research in some points or whatever you
need on this topic please post a request of an answer clarification, I
will be glad responding to your requests.
Also your feedback is a valuble tool for us, so when this answer will
be finished please tell me how this answer works, this will help me
and my fellows researchers to give a better service.
Thank you.

Best Regards.
livioflores-ga
Comments  
Subject: Re: Firewalls Benchmarking Research
From: njyoder-ga on 19 Apr 2003 02:21 PDT
 
In response to:
'"Tiny Personal Firewall" 
 
This a full featured firewall which includes a system security suite.
I tested it in my PC and had severals troubles trying to keep my
computer working with this product installed and running. It was a
severe problem trying to install new software after firewall
installation. Next step was see some reviews; the better one is, from
PC Magazine:
http://www.pcmag.com/article2/0,4149,643041,00.asp'

I find it very odd that you say this.  I'll start by going into what's
wrong with the PC Magazine article you mention.  The tests said that
TPF failed to detect the port scan, and failed the MAC and NetBIOS
tests.  This indicates they didn't know what they were doing, as it's
trivial to configure TPF to block these with a little knowledge of
networking.  They indicated problems with AIM and AOL which is odd
since (IIRC) TPF can dynamically update rules for running programs
(they stated the opposite).  This is not to mention the fact that TPF,
just like Kerio Personal Firewall, has a mode for learning new rules. 
This mode prompts the user for every unknown program, even though they
misleadingly stated that it allowed all programs to be trusted by
default.  Obviously they didn't enable this (or foolishly created a
rule that allowed to much traffic), which is a huge oversight on their
part because it blocks programs by default unless you allow them to go
through.  My point is, is that these reviewers didn't know what they
were doing when testing TPF and their review reflects that ignorance.

The second part of this is which is odd is that you gave a good review
to Kerio Personal Firewall.  Kerio Personal Firewall is basically the
same as Tiny Personal Firewall.  Kerio Technologies bought Tiny
Personal Software from Tiny Software, added some minor improvements,
fixed some stability bugs and released a free version of it.  So KPF
is really just a minor version increase over TPF.

The only major gripe with TPF that I've had is some stability issues
when enabling/re-enabling the network on Windows 2000 (which caused a
BSOD a few times).  Though I rarely  do that anyway, so it's more of a
non-issue.
Subject: Re: Firewalls Benchmarking Research
From: livioflores-ga on 21 Apr 2003 20:16 PDT
 
Hi njyoder!!

I think you are in a mistake. At present, Tiny Firewall is a very
different software than the original (before it becomes Kerio). Some
people from the former Tiny Software developed a complete new
firewall. You are talking about the last free version of Tiny Personal
Firewall and I am talking about the latest version of Tiny Personal
Firewall which is a paid software, and all the software works in a
complete different way than the version that you commented here.
Download (and try) the new version from:
http://www.tinysoftware.com/

The current version is the v4.5 and since the v3.0 Tiny Personal
Firewall is a paid software and has a different architecture that the
free version 2.x. This version (2.x) is the version similar to the
Kerio Personal Firewall.
I evaluated the version 4.x.

I hope this clarify the confusion.

Best regards.
livioflores-ga

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy