D-Link DFL-700 Firewall

This richly-featured gateway and firewall allows IT managers in small/medium-sized businesses to secure their networks easily.… Read full review

Typical price: £382

Pros

  • Easy to use and configure
  • provides complex security for those who need it
  • rich feature set
  • complete gateway in a box

Cons

  • Needs some familiarity with IP
  • little or no configuration available for intrusion detection
  • relatively expensive

In these high-risk times, firewalling your network is a necessity rather than a luxury. And with a small or medium-sized business network, it makes sense to use a separate, dedicated appliance to minimise configuration time. The alternatives are either to run a software firewall on one of your servers, which can lead to high configuration requirements, or hope that the firewall in your router is up to scratch.

The box itself is a standard D-Link design, with status lights on the front and three Ethernet ports to the rear -- LAN and WAN obviously, but also a DMZ (De-Militarised Zone) in which you can place your Web, mail or FTP servers. You would normally relax your Internet traffic filters for the DMZ, as they are applicable only to externally-accessible servers, not the whole network. This means uninvited traffic from the outside world never traverses your local network, making the LAN just that bit safer. The DFL-700 provides complete firewall functions. Setup can be performed mostly using drop-down boxes (for instance, you select the IP service whose packets you want to either drop or allow), which makes setup easy and quick. You can create separate rules for any combination of the three ports in either direction. If you want to delve deeper, all service filters are configurable. Should unauthorised traffic get as far as the LAN, an intrusion detection system allows you to log attacks, locate the source IP address, notify you by email and set up policies to restrict incoming traffic from specific IP address sources. Similarly, unwanted data can be prevented from entering the network based on IP address, content or both. You can set up your own black and white lists, providing content filtering if required. The system's default blacklist is set up to strip off all attachments that could open up vulnerabilities or carry viruses, worms or Trojans. If you need to provide secure access to your network from outside the office, the DFL-700 allows you to set up a virtual private network (VPN), secured by the latest IPSec encryption technologies. Bandwidth management allows you to both limit and guarantee bandwidth for particular services such as Web browsing. What D-Link has produced is more than just a firewall, though. It also supports network and port address translation (NAT and PAT), so you can hide and keep separate the IP addresses used on the LAN, transparent mode, routing mode and SPI. It allows you to authenticate users via certificates using a RADIUS server and a certificate authority, and encourages you to use encrypted HTTPS connections, especially for admin. The box also includes a DHCP server that can allocate IP addresses to new network devices and a DNS server for translating IP addresses into friendlier hostnames, and vice versa. Its configurable routing tables also mean that it can become a gateway between the LAN and the public network. If you want a VPN connection to your network from elsewhere, or you have externally accessible servers, the DFL-700 can register with DynDNS services, which allow dynamically allocated public IP addresses to be located using DNS. All events can be logged, and you can view reports of both events and CPU usage using graphically displayed statistics. The easily accessible help system is clearly written, Telephone support is available on an 0845 number between 9am and 6pm, and the product is covered by a two-year return to base warranty. Most small and medium-sized businesses will find that the DFL-700 meets all but the most arcane requirements. And if your needs outstrip the DFL-700's capabilities, D-Link has said it will soon launch a DFL-1000 for more complex networks.

Related stories

Member reviews

Member's rating:
  • 8.50 out of 10
8.50 out of 10
Reply 29 Apr 04 17:37 Reply

I guess this is a smaller version of the Clavister Firewall.

Member's rating:
  • 9.50 out of 10
9.50 out of 10
Reply 23 Nov 04 13:12 Reply

- expensive
- slow VPN-connections
+ easy to configure
+ "Fail safe mode"
- Connections with PPPoE not possible

Member's rating:
  • 6.00 out of 10
6.00 out of 10
Reply 18 Jan 05 15:31 Reply

more than 4 months and yet support did not solve a VPN issue for me.

Member's rating:
  • 3.50 out of 10
3.50 out of 10
Reply 17 Mar 05 11:35 Reply

Member's rating:
  • 9.00 out of 10
9.00 out of 10
Reply 28 Aug 05 22:26 Reply

Outstanding security appliance. Setup took a bit but once setup, it has functioned as advertised. WW

Member's rating:
  • 10.00 out of 10
10.00 out of 10
Reply 20 Jun 06 01:41 Reply

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

Boobjob

Sometimes I get sad. And then I dance in circles til I'm dizzy and I feel better. Twitter doesn't want me but I'm good enough for ZDNet. That...

4 hours ago by Boobjob
DEEPWOE

Twitter announces @Anywhere tool http://www.zdnet.co.uk/news/it-strategy/2010/03/16/twitter-announces-anywhere-tool-40088318/

Luis_Corrons

How the butterfly botnet was broken (via ZDNetUK) - http://bit.ly/c6AV8K

Boobjob

Sometimes I get sad. And then I dance in circles til I'm dizzy and I feel better. My cat doesn't want me but I'm good enough for ZDNet. That...

4 hours ago by Boobjob on UK copyright law to be changed 'without scrutiny'
CA

"Watson noted that "the logical thing to do would be to remove the copyright changes from the bill and start again [with those changes] after the...

4 hours ago by CA on UK copyright law to be changed 'without scrutiny'
meck

hi

4 hours ago by meck on Mobile phones to be tested on Tube
CA

I don't like it, it its like loading into a shoe box, if it got any more claustrophobic it would have its hands around your throat. I can't...

5 hours ago by CA on ZDNet UK: faster, smarter, still IT all the way
CA

I don't like it, it its like loading into a shoe box, if it got any more claustrophobic it would have its hands around your throat. I can't...

5 hours ago by CA
Rupert Goodwins

Yes, we still have some problems with editing community stuff (last time I looked, edits didn't seem to go through, but did after far too long a...

5 hours ago by Rupert Goodwins on Welcome to the new ZDNet UK community!
Rupert Goodwins

Yes, we still have some problems with editing community stuff (last time I looked, edits didn't seem to go through, but did after far too long a...

5 hours ago by Rupert Goodwins
stripyshirtguy

Your avatar is showing in the ZDNet Live box ;)

5 hours ago by stripyshirtguy on Welcome to the new ZDNet UK community!
Xwindowsjunkie

Now its working, sort of. BTW my dog is upset that he's no longer my avatar. He wanted me to complain.

5 hours ago by Xwindowsjunkie on Welcome to the new ZDNet UK community!
Xwindowsjunkie

Can't edit my profile, yet it reports it has been changed.

5 hours ago by Xwindowsjunkie on Welcome to the new ZDNet UK community!
Subliminal

Er did Mollett really say ennervated? that means the opposite of energised y'know..

6 hours ago by Subliminal on Rights holders vs digital rights activists - who wins?
softwaredir

Security Bullet In - ZDNet UK (blog) http://www.zdnet.co.uk/blogs/security-bullet-in-10000166/ via http://redir.is/isf

Kazoo

It would be good to know exactly how much negotiation is going on behind the scenes to get the bill sorted out before the election.

7 hours ago by Kazoo on Rights holders vs digital rights activists - who wins?
Rupert Goodwins

Well, let us know what sort of specific groups of articles you want to look for and we'll see if we can find a way for that to happen. No promises...

7 hours ago by Rupert Goodwins on ZDNet UK: faster, smarter, still IT all the way
Rupert Goodwins

And so the importance of code auditing is once again revealed. Bet that nobody will change the way they buy in IT as a result, though.

8 hours ago by Rupert Goodwins on IT security insiders rob casinos of £33,000
Tezzer

Hmmm. I'll reserve judgment at the moment. Looks pretty, but so far doesn't seem to easy to find specific groups of articles. Maybe I'll get used...

8 hours ago by Tezzer on ZDNet UK: faster, smarter, still IT all the way
riptari

Loving the new look #zdnetuk. Big pats on backs all round guys

Latest in Security

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now