Deepnet DualShield

 

Product Information

Price:£495 for five-user starter pack

Product Rating

Features star star star star ¾
Ease of Use star star star star star
Performance star star star star star
Documentation star star star star ¾
Support star star star star star
Value for Money star star star star star
Overall Rating star star star star star
For:Huge feature set, supports wide array of platforms, well documented
Against:Could possibly be overkill for smaller implementations; no syslog support we could find
Verdict:Good choice for full-featured authentication tool. Recommended

Related Group Test

Reviews For This Vendor

Multi-factor authentication is easy to do for workstation and server logins, but what about your web-based applications? With its DualShield product, Deepnet Security offers a solution that can add that extra layer of security to those applications - at a very reasonable price point.

For testing, we were presented with a series of install files and a SafeID Oath token. There are several ways to deploy DualShield - an administrator can combine all modules onto a single server, or break out the front- and backend components to different locations. In addition, multiple database types are supported that makes it extremely flexible. In the end, we chose to perform a basic install, placing all components on a single server and allowing the installer to configure a MySQL server and database instance for us.

Since we wanted to begin the testing by setting up basic two-factor authentication with a workstation, we also had to install the Windows login agent on the server and client software on the workstation. The client software installation was simple and straightforward, however the agent portion of the software requires, somewhat counter intuitively, that it be registered to the authentication server before installing it. We then set up a link to Active Directory as our identity source, set up a basic Windows logon procedure, and linked the Oath token to our test account.

The steps to configure the product appeared more complicated than they actually were, and by following the documentation we had our basic installation and configuration complete within an hour.

Although DualShield can secure Windows, Mac and even VMware View workstations, it offers much more than simple workstation authentication. The product supports a wide array of authentication methods, including: token-based one-time passwords; on-demand passwords; biometrics; device DNA; and PKI certificates. The software even supports sending an on-demand password via Twitter - which we find absolutely bizarre - but we suppose it's a further testament to the flexibility of this product. The single sign-on module is SAML 2.0 compliant, so cloud-based applications such as Google Apps or Salesforce are easily managed. IIS applications can be secured via the IIS agent module. VPN support is provided for Cisco, Check Point, Juniper Networks and F5 Networks concentrators, as well as any VPN supporting Radius, however it is divided between SSL VPNs and IPsec.

While SSL VPN access can be augmented with any authentication method DualShield supports, IPsec VPN access is limited to one-time password methods due to limitations in Radius. The self-service module allows administrators to enable their end-users to reset passwords, request replacement tokens or even request an emergency login code. DualShield also offers a decent logging system that allows administrators to monitor all events or a subset of events, and the organisation of it proved very useful during troubleshooting. Unfortunately, there is no syslog support that we could find, so any log viewing needs to be done on the product management console. A small sacrifice, considering everything else you get.

Documentation was extremely thorough. Deepnet has prepared implementation guides for a number of common products, including Cisco, F5 Networks, Juniper Networks, Outlook Web Access, VMware and others, along with more general guides for incorporating DualShield into custom IIS apps and SAML 2.0 compliant cloud services. The documentation was easy-to-follow, with plenty of screenshots, however there wasn't any bookmarking so we found ourselves scrolling around a lot.

Deepnet has broken its support offerings into three tiers: basic gets you eight-hours-a-day/five-days-a-week email and web support; standard includes the basic features, but adds phone and WebEx sessions; and premium expands the standard package support hours to 24/7. During evaluation periods, its eight-hours-a-day/five-days-a-week standard support package comes free.

The product licensing is based solely on a per user licence model - all modules and features are included. A five-user starter pack can be purchased for £495.

 
 
 

SC Featured Webcast

Employee file sharing: the good, the bad and the ugly

Streaming live on 4th June 2013 at 3pm GMT

This new webcast is set to unveil the full results from the latest data security survey, where it was revealed that 50 per cent of the information security professionals asked said that they had 'no real visibility' of how data is being sent within and outside the company. Guest speakers include the director of information security from Monster.co.uk and the ISO from Atos. To secure your free place, please click here.

SC Webcasts

Security beyond the (fire)wall

Streaming live on 6th June at 3pm BST

This webcast addresses the technological challenges of maintaining full control of your most sensitive information - even once it goes beyond the firewall - while maintaining the freedom and flexibility necessary to allow your staff and other stakeholders to work as efficiently as possible. Tune in for free to hear from our regular and popular guest speaker, Bola Rotibi from (ISC)2 application security advisory board. To secure your place, please click here.


2013's invisible network threats: Identify and respond

Streaming live on 11th June at 3pm BST

In a recent SC survey, when asked 'Do you think your current network is secure?' 43 per cent of IS professionals said they were not sure. Technology developments such as multi-point cloud solutions, consumerisation, BYOD uptake and even Windows 8 are a major headache in network security for IT leaders. So what can be done? SC's latest webcast shares practical advice from industry experts. To secure your free place, please click here.

SC Whitepapers

Java security: Balancing existing testing platforms with open source solutions

In a rush to get new products out to market quickly, companies expose themselves to the risk of software failure. Java developers often turn to open source solutions to help protect themselves from risk. This new whitepaper explains how you can use your existing testing platforms alongside open source solutions to fix those issues related to both security and quality within your Java code. To download the paper for free, please click here.


DDoS and downtime: Considerations for risk management

The purpose of this paper is to start a conversation about the often overlooked risk of downtime caused by DDoS attacks and to provide sufficient content for risk managers to account for the DDoS threat as they evaluate risks to their day-to-day operations and long-term mission. To read the paper in full, please download it for free here.


Ponemon 2012 Global Encryption Trends Study

In Ponemon's recent Global Encryption Study, the organisation surveyed 4,205 information security professionals across seven countries to examine how encryption has evolved over the last eight years. The study focused on data protection priorities, budgeted expenditures for encryption and the types of encryption technologies involved, with the findings revealing some interesting insight into the relationship between encryption and its impact on the security position of organisations. To read the full report for free, please download it here.


Advanced spear phishing: The rise of industrial phishing attacks

With phishing still the most common form of attack, hackers are now engaging in industrial-scale phishing attacks that leverage sophisticated customisation and delivery techniques. Borrowing tactics from cloud computing and database marketing, this study looks at longline phishing - an advanced form of spear phishing, which has higher clickthrough and penetration rates than traditional attacks, potentially causing a higher risk to IT security departments across the world. To read the study for free, please click here.


Home | News | Products | Whitepapers | Jobs | Subscribe | Contact Us | About Us | Advertising | Sitemap | Editorial | Subscribe to our RSS feeds RSS

This material may not be published, broadcast, rewritten or redistributed in any form without prior authorization.

Your use of this website constitutes acceptance of Haymarket Media's Privacy Policy and Terms & Conditions