Rolling Review: Layer 7 SecureSpan XML Networking Gateway
The first entry in our all-in-one SOA appliance review shows that increased competition means lines between product categories are blurring -- and IT is benefiting.
The SecureSpan appliance is available with built-in XML acceleration |
THE UPSHOT |
|
CLAIM:
Layer 7's SecureSpan XML Networking Gateway is a hardware-accelerated XML firewall and service gateway. Its main purpose is to protect Web services and mediate communications between service consumers and providers, without slowing things down. CONTEXT: Layer 7 Technologies is aggressively pursuing the XML appliance market by increasing the breadth of functionality in its products. With version 4.3 of the SecureSpan SOA appliance, Layer 7 takes a step toward realizing its vision of a hardware-enabled enterprise service bus. In addition to a wide variety of SOA security features, the SecureSpan gateway sports content inspection, data transformation, protocol switching, and SLA enforcement features. CREDIBILITY: Layer 7 lived up to its claim to support standards such as WS-Security 1.0, SAML 1.1 and 2.0, SSL 2.0/3.0, and JMS 1.0. Our testing showed that SecureSpan provides convenient mechanisms for defining and managing policy information. |
Since Cisco Systems acquired Reactivity last year, the XML appliance market, for the most part, has been quiet. But next door, Layer 7 Technologies and Vordel continue to be aggressive players in the XML security gateway area. And they'll need to be tough--the core function of an XML security gateway is an XML firewall, and this is a service that established firewall vendors like Cisco, Juniper Networks, and F5 Networks all believe they're well-positioned to provide.
More Software Insights
Webcasts
- Best Practices for Improving Database Testing: Upgrades, migrations, business growth and more - ensuring you can handle the workload!
- Insurance Workforce Optimization: How To Work Smarter To Benefit Your Customers, Employees and the Bottom Line
White Papers
- Smart Infrastructure for Todays Heterogeneous Business Applications
- The Cloud A New Home for Enterprise Content and Collaboration
Reports
More >>As standalone XML appliances become poster children for market consolidation, which vendors survive is an open question. What's not up for debate is that IT is reaping the benefits of this features competition as we seek to secure and manage our growing service-oriented architectures. As proof, witness the breadth and depth of functionality packed into Layer 7's latest SecureSpan XML Networking Gateway SOA appliance. Not only did SecureSpan control how the Web services in our test bed were exposed to and accessed by partners and customers, it provided us with runtime control over service-level authentication, authorization, key management, credentialing, integrity, confidentiality, schema validation, content inspection, data transformation, threat protection, routing, protocol switching, service-level agreement enforcement, logging and auditing, and other functions.
We took the 1U Layer 7 SecureSpan XML Networking Gateway appliance out for a test drive in our Synegen Real-World Partner Labs. While the amenities of the hardware appliance, primarily setup and maintenance interfaces, could have been better, we had no problem getting the device running and configured. Once under way, we were pleasantly surprised by the operational features and power that the SecureSpan Gateway provided.
FIRE IT UP
The device's configuration interface can be accessed either through a USB keyboard and monitor or via a serial management port on the back of the appliance. In our testing, both worked without a hitch. Once the system was configured, we preferred to access SecureSpan Manager through its client interface because the Web console is somewhat lacking in features. We did appreciate that SecureSpan Manager provided us with a set of predefined roles to control user permissions, a real time saver.
The SecureSpan appliance is essentially a proxy that runs inside an Apache Tomcat container with a MySQL database on the back end. The Tomcat container hosts the processing layer, which manages factors such as identity providers, the trust store of certificates, integration with UDDI registries, and logging and auditing functionality, while the database is responsible for storing this and other configuration information.
|
NUTS AND BOLTS
|
|
FEATURED PRODUCT: Layer 7 Technologies' XML Networking Gateway, hardware appliance, $80,000; virtual appliance, $35,000 ABOUT THIS ROLLING REVIEW: he focus is on SOA appliances. To qualify, products must provide XML security, acceleration, transformation, and parsing functionality. We're evaluating based on ease of installation and configuration, breadth of functionality, management capabilities, features, and price. Each vendor must provide pricing for a product configuration capable of acting as an XML security gateway in connection with XML acceleration requirements. NEXT UP: Vordel XML Gateway OTHER VENDORS INVITED: IBM and Cisco Systems. Contact the author at epieczkowski@nwc.com for consideration. |
LOCK DOWN SERVICES
Policies define rules for how a SecureSpan-protected service can be consumed. Initially, we were somewhat overwhelmed by the number of different types of policies we could configure. The good news is Layer 7 provides convenient mechanisms for defining and managing policies. The bad news? These features have limited functionality in the browser-based version of SecureSpan Manager.
Once our policies were defined, we were able to limit services by HTTP basic authentication, XPath credentials, and service availability. This is on top of the automatic threat protection that was enforced against all manner of exploits, including TCP/IP-based attacks, coercive parsing, XML bomb and external entity attacks, schema poisoning, WSDL scanning, and XML routing detours. The SecureSpan integrates with a number of SOA registry and governance products for policy management.
The appliance sits on top of a powerful AMD Opteron processor-based Sun Fire X4150 server with a Sun Crypto Accelerator 6000 PCIe Card to accelerate SSL cryptographic functions. Its SSL performance was impressive, and while admiring the dashboard to monitor service metrics in real time, we noticed that the longer we let our tests run, the more performance improved. The device's Tarari RAX PCI-e XML accelerator card enhances performance for XPath expressions, XML schema validation, and XSL transformations.
Layer 7's SecureSpan XML Networking Gateway is a solid product that offers a lot of functionality out of the box. We'll see how it stacks up as we test its rivals as part of this Rolling Review. Look for our comprehensive comparison chart and report card after we've completed testing.
Erik Pieczkowski is an enterprise architect and partner with Synegen. His experience ranges from design and development of high-performing, message-driven systems to building and deploying scalable SOAs. Write to him at epieczkowski@nwc.com.
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Subscribe to RSSResource Links
Related Webcasts
- Unlock the Value of Your Business Data: IBM's Integration Solution for .NET Environments
- Techniques for Next-Gen Data Protection using Next-Gen Computing
- Collaborative DevOps: Bridging the gap between development and operations with automation
- Best Practices for Improving Database Testing: Upgrades, migrations, business growth and more - ensuring you can handle the workload!
- Insurance Workforce Optimization: How To Work Smarter To Benefit Your Customers, Employees and the Bottom Line
This Week's Issue
Free Print Subscription
SubscribeCurrent Healthcare Issue
- InformationWeek Healthcare CIO 25: Our second annual honor roll of the health IT leaders driving healthcare's transformation.
- EHR Unreadiness: Only a small percentage of physicians planning to apply for Meaningful Use funds have e-health record systems capable of achieving most of the requirements. .
- And much more!
- Read the Current Issue
Related Whitepapers
Featured Broadcast
Organizations must rigorously protect their data from all threats - including theft by outsiders and insiders, malicious attacks that can distort or destroy data, and inadvertent corruption or misuse by employees.Download this white paper and find out how to safeguard data and fulfill compliance mandates.
Learn More












