7 out of 7 people found this review helpful.
Basic VPN with limited users
Date of Review: Jul 5, 2004
The Bottom Line: Make sure you get the 5GT Plus if you need it. Upgrading the 5GT is painful. Save $1000 and try a Soekris VPN instead.
I purchased two NetScreen 5GT to connect a remote office with the main office, via a VPN. The Netscreen was intended to replace an aging, slow Intel Netstructure VPN. Installation of the NetScreen was very easy, and our network administrators in both offices were able to get the device up and running in about 10 minutes with minimal telephone coordination.
The NetScreen routed encrypted packets perfectly well, and it was much, much faster than the Intel VPN, but it had a hidden limitation: it only supported 10 endpoints (called users). We immediately noticed this limitation, as some of our computers could communicate with the home office and some could not. As it happens, our sales representative at the NetScreen failed to mention this small detail.
If you need more than 10 endpoints on your network, you must purchase the NetScreen 5GT Plus, a $700 upgrade to the 5GT. The "upgrade" consists of a password that you type into your NetScreen to let it know you shelled out the big bucks. You can't get this upgrade directly from NetScreen sales, either. In true 1980's fashion, you must deal with their unreliable, incompetent network of resellers. We sent our $1400 to a reseller in New York, and after a month (yes, a month!) we had still not received our piece of ASCII text. It was necessary for us to hassle NetScreen headquarters to get their resellers to perform. Eventually, after much shouting into telephones, we got our upgrade, and the NetScreen's artificial limitation was lifted.
Now that we have the equivalent of a 5GT Plus, we are fairly happy with the product. The only drawback seems to be establishment of VPN sessions. The VPN establishes separate sessions for each endpoint pair, and this can cause a small delay. It would be preferrable to simply establish a persistent IPSec tunnel to the remote VPN and route all traffic over that, but the NetScreen works differently. Even so, it is faster than the Intel and that was the objective of the purchase.