Survey
* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project
* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project
SANGFOR Next Generation Firewall (NGFW) Next-Generation security for your business SANGFOR Next-Generation Firewall is designed with application control, intrusion prevention and web security in mind to deliver excellent visibility over users, applications and contents. SANGFOR NGFW ensures the entire security from layer 2 to layer 7 at multi-gigabit speed and distinguishes itself from the traditional firewall, making it the ideal choice for customers. Entire application security protection Bidirectional content inspection Intelligent security defense system Application layer high performance Product Features Entire security Firewall Authentication & Visibility Static and dynamic package filtering. User Mapping by IP, MAC, IP/MAC binding, hostname and USB-Key. authentication User account import from CSV file and LDAP Server. Inspection on well-known protocols of FTP, HTTP, SMTP, RTSP, H.323 (Q.931, H.245, RTP/RTCP), SQLNET, NMS, PPTP, TCP, UDP… Seamless integration with AD and LDAP, Policy based SSO integration with AD domain, proxy, POP3 and WEB, Protection against attacks of Land, Smurf, Fraggle, WinNuke, Ping of Death, Tear Drop, IP spoofing, SYN/ICMP/UDP flood, HTTP GET flood, DNS query flood, ARP cheating, ICMP redirection, static and dynamic black list, etc. Intrusion Prevention Scanning based on signature, protocol or applications. Intelligent analysis of unknown threats with correlation analysis. Application control Identify applications based on application signatures database. URL filtering On-disk URL database,Anti-proxy technology. Support application based control policy. Support URL category and group based policy. Up-to-date CVE Compatibility certificated IPS database of 3000+ signatures. Server and terminal group signature database flexible for policy deployment. HW&SW Visibility Real-time monitor on CPU, memory, disk, session, online users and network interface information. BM Visibility Bandwidth usage ranking by IPs, applications and users. Security Visibility Detailed real-time information on security issues for servers or terminals, including source/destination IP, attack category and URL, etc. Policy based IPS protection on source/destination IP and subnet. Block worms, Trojans, spyware, scanning, DoS, DDoS, vulnerability exploits, buffer overflow attacks, abnormal protocol and attacks with evasive tactic employed. Networking and optimization Deployment Gateway, Bridge, Bypass mode, virtual wire and mix mode. Detailed log message and in-cloud threats analysis. Networking Support ARP, DNS, IP UNNUMBERED. Support policy routing, static routing, RIP v1/2 and OSPF. Anti-virus Stream-based anti-virus for HTTP, FTP, SMTP and POP3 protocols, etc. Up-to-date anti-virus database with 300,000+ signatures updated manually or automatically. Build-in SOPHOS anti-virus database and engine. Web Application Security Support application policy-based forwarding. , Up-to-date application signature database of 2000+ web application threats. NAT Build-in IPsec VPN Built-in route-based IPsec VPN for secure, fast and cost-effective deployment of remote office network. Bandwidth management Support multiplexing and intelligent routing Weak password protection for ftp and telnet, etc. Server information invisibility for web server and ftp server, etc. DLP Management Build-in sensitive information signature database and support user-defined sensitive information, such as username, password, mailbox, ID and MD5 keys. Configuration Port and service scanning for certain IP and assess the security risk for the server or terminal. Support weak password for FTP, MYSQL, ORACLE, MSSQL, SSH, RDP, NetBIOS and VNC services, etc. Automatically generate the cross-module security policy for FW, IPS and WAF module to ensure the entire security. Support Web GUI with SSL encryption; Support SNMP. Alarm Ensure high security for sensitive information of the database against leakage. Risk Assess Management File uploading scanning and filtering based on signatures Prevent information leakage through HTTP connections. Advanced P2P control. Qos policy based on users, applications, IPs, file types, website types and schedules, etc. Black list and exclusion list of URL. Protect web application against the top ten threats defined by OWASP, including SQL injection, XSS attack and CRSF, etc. 1:1 NAT, n:n NAT, m:n NAT, time based NAT policy. Support NAT ALG, including DNS, FTP, H.323 and SIP, etc. Support E-mail, MSM alarms on sign-in, virus, IPS, web attack and hardware issues. Support graphical tools for trouble shooting Support template configuration for easier maintenance. Reporting Risk Report Support security risk report based on port, service, vulnerability and weak password providing guideline for IT administrator. Security Logs Detailed loges for security events as DOS attack, web attack, IPS, viruses, website access, application control, user login and OS configuration. Support schedule based trend report. Trend Report Support user defined statistics report based on IP, group, Statistics users, application in flexible report schedule Report Report Format Support XML, PDF format and automatically send to specified email list. www.sangfor.com SANGFOR Next Generation Firewall (NGFW) NGFW Product Family Model S5000-F-I M5000-F-I M5100-F-I M5200-F-I M5300-F-I M5400-F-I M5500-F-I M5600-F-I M5800-F-I Profile Mini 1U 1U 1U 1U 1U 2U 2U 2U 2U 2G 2G 2G 2G 2G 4G 4G 8G 16G 24G HD Capacity 320GB 320GB 320GB 320GB 320GB 320GB 500GB 500GB 500GB 500GB Firewall throughput 1 Gbps 1 .5Gbps 2 Gbps 3 Gbps 5 Gbps 8 Gbps 12 Gbps 18 Gbps 20 Gbps 25 Gbps RAM Firewall throughput M5900-F-I 50 Mbps 100 Mbps 200 Mbps 400 Mbps 500 Mbps 700 Mbps 1 Gbps 2 Gbps 5 Gbps 10 Gbps IPS & WAF throughput 35 Mbps 70 Mbps 100 Mbps 150 Mbps 300 Mbps 500 Mbps 650 Mbps 1.3Gbps 3.8Gbps 6.8Gbps New sessions per second 10,000 11,000 13,000 20,000 30,000 50,000 90,000 150,000 200,000 300,000 500,000 1,000,000 1,200,000 1,500,000 1,800,000 2,100,000 2,300,000 6,000,000 8,000,000 (APP & URL enabled) Max concurrent session 15,000,000 Power and Physical Specifications Dual Power Supplies N/A N/A N/A N/A N/A N/A √ √ √ √ Power [Watt] (Typical) 60W 60W 60W 100W 100W 250W 300W 300W 500W 500W Temperature 0~ 40℃ 0~ 40℃ 0~ 40℃ 0~ 40℃ 0~ 40℃ 0~ 40℃ 0~ 40℃ 0~ 40℃ 0~ 40℃ 0~ 40℃ Relative Humidity 5%~95% 5%~95% 5%~95% 5%~95% 5%~95% 5%~95% 5%~95% 5%~95% 5%~95% 5%~95% non-condensing non-condensing non-condensing non-condensing non-condensing non-condensing non-condensing non-condensing non-condensing non-condensing System Dimensions (W×L×H mm3) 275x175x 44.5 430x300x 44.5 430x300x 44.5 430x300x 44.5 430x300x 44.5 430x430x 44.5 440x500x 89 440x500x 89 440x500x 89 440x600x 90 System Weight 1.5 Kg 3.9 Kg 4.0 Kg 4.2 Kg 4.25 Kg 7.0 Kg 10.9 Kg 18.0 Kg 19.0 Kg 20.0 Kg NA NA 1 pair 1 pair 1 pair 1 pair 2 pair 3 pair 4 pair 4 pair 10/100/1000 3 4 4 6 4 8 8 10 8 8 1G Fiber SFP - - - - 2 - 2 4 4 - 10G Fiber SFP - - - - - - - - - 2 Network Interfaces Bypass (copper) SANGFOR TECHNOLOGIES CO., LTD [email protected] www.sangfor.com Global Service Center: +60 12711 7129 (7511)