Digit-Life :: Computer Hardware In Detail
  Articles Subscribe to the reviews RSS feed  Subscribe to reviews via Feedburner  Subscribe to reviews by e-mail
July 23, 2008
Conroe vs. Wolfdale: To the Limit

Test results of Core 2 Duo E6550, E6850, E8200 and E8500.

Lower- and Higher-End Phenom X3/X4 Processors

On the background of Core 2 Duo E4x00 series.

July 17, 2008
i3DSpeed, June 2008

Added test results for GeForce GTX 260/280/SLI, RADEON HD 4850/4870.

July 15, 2008
ATI RADEON HD 4870 X2 (R700) 2x1024MB Preview

A serious threat to NVIDIA.

July 14, 2008
ATI RADEON HD 4870 512MB

Consolidating market success.

July 10, 2008
ATI RADEON 4850 512MB

2.5 times the shaders on the example of 4 graphics cards.

July 8, 2008
ECS A740GM-A Motherboard on AMD 740G Chipset

What an entry-level intergrated board should be?

GeForce 9600 GT Triplet

Some very interesting and original products from Gainward and Forsa.

July 7, 2008
XFX nForce 790i Ultra 3-Way SLI and Zotac nForce 790i-Supreme

Two motherboards on NVIDIA nForce 790i Ultra SLI chipset.

July 3, 2008
AMD 780G/780V/740G Integrated Socket AM2+ Chipsets

Hybrid CrossFire and High-Definition video.

More articles »

U.S.Robotics Secure Storage Router Pro (USR8200)

Rate it






Features of the embedded SMB and FTP servers







As it has already been said in excursus to settings, you can connect external data storage devices with USB or Firewire interfaces to USR8200. The storage devices at once appear (if detected) in Network map, where you can browse them, create partitions, format, or check for errors.

Unfortunately (this is noted on the web site of the manufacturer in the firmware comments), compatibility with USB 1.1 devices leaves much to be desired. Out of ten flash cards that I tried to connect, only two worked: Kingmax 16Mb and Easydisk 128Mb. I had no devices with USB2.0 or IEEE 1394 available, and so I didn't manage to check how USR8200 works with them.



Users will see such storage devices as shared disks (SMB resources) or via an FTP server. Access to both kinds of resources is granted only to users, who have logins and passwords in the corresponding section of USR8200. Besides, an ftp server can have a special anonymous user. This user can have read and write rights. You can also create a special directory, and this user will not be able to go any higher than that (chroot). But in Samba (this program serves as an SMB server) anonymous access is not provided.






Much to my regret, implementation of user access isolation is in germ. If you grant read access to a user, this user will be able to read all files from the medium. If you grant write rights – in much the same way, this user will be able to write and delete any files. You can see why it is so in the screenshot above: the files listed on the screenshot were created by different users via ftp and smb, but they all actually have one owner or group. This concerns the files created by anonymous users via ftp as well.



USR8200 security tests

The tests were carried out according to this technique.

The device has been scanned in two modes. The first mode featured the minimum security policy (all inbound and outbound connections were allowed) and the activated access to configuration interface on WAN:







Nessus reports:

Obviously, a lot of various problems are found as a result of full access (in reality, this configuration will hardly be chosen). But it should be noted that no serious vulnerabilities were found.

During scanning the device was operating all right, there were no reboots or freezes. But the security logs showed almost no signs of attack attempts or scanning.

Before the second scanning, we set the security policy to "block everything" and deselected all check boxes in Remote Administration (all possible access from outside was blocked). I will not publish Nessus reports, because there aren't any. That is nothing was found during scanning.

In other words, device security is on a high level.


Availability

Unfortunately, USR820 was not on sale when the review was written.


Conclusions

Secure Storage Router Pro (USR8200) from U.S.Robotics is a functional and a high-performance device. One can even say that it's a first device (in our lab), which possesses such an impressive set of functions, high performance, as well as a good security level.

If programmers corrected several bugs about access right isolation for users working with embedded SMB and FTP servers and some glitches in IPSec implementation, there would be practically nothing to nag at. Another obscurity – the device has the IPSec support and the console mode of control via telnet, why not add the ssh support?

Pros

  • High routing performance (transfer between the LAN and WAN segments)
  • IPSec/PPTP VPN server
  • High performance of the embedded VPN server supporting IPSec
  • Very rich settings of the IPSec protocol (including tunnel and transport mode support)
  • Good performance of the embedded VPN server with the PPTP support
  • IPSec/PPTP pass-through support
  • Good security level
  • Flexible and functional firewall
  • Very detailed logs
  • SNMP protocol support
  • Embedded print server
  • Embedded file server supporting SMB and FTP
  • Remote control via telnet

Cons:

  • It's impossible to add anonymous users to the IPSec server (without specifying an IP address)
  • Implementation of the IPSec tunnel establishment algorithm does not allow to connect to a remote host directly (at minimum, you need another host specified as a gateway on WAN interface)
  • L2TP pass-through is not supported
  • Domain filtering does not support masking
  • Some ambiguity with content filtering by subscription
  • Lack of the external syslog server support (logs are stored locally or can be partially sent to emails)
  • Possible incompatibilities with USB1.1 devices
  • Certificate support in IPSec is not convenient, Radius server integration is not supported
  • SSH control is not supported
  • No anonymous access to a file server for Samba
  • Primitive user access isolation on a file server (the owner of all files is the admin user)



Navigation:



Evgeniy Zaitsev (eightn@ixbt.com)
24 August, 2004




Comments

Report bugs   Register       


  Total: 0

Platform & Cooling · Graphics Cards · Multimedia & ProAudio · Notebooks & Handhelds · Other Devices · Shopping


Advertise With Us · About Us · Affiliates · Forum


Copyright © 1997—2008: Byrds Research & Publishing Ltd. All rights reserved.
Design by Explosion & Artem Pavlenko. Programming by Sergey Anokhin.